HomeSecurityApache Tika: Risk from vulnerability that was fixed months ago

Apache Tika: Risk from vulnerability that was fixed months ago

A vulnerability in the widely used tool Apache Tikamay have much more serious vulnerabilities than initially thought, according to the project's administrators. The vulnerability was first disclosed last summer. But a new advisory addresses two related vulnerabilities, CVE-2025-54988 reported in August (severity rating 8.4), and CVE-2025-66516 , reported last week, with a severity rating of 10.

See also: Critical vulnerabilities in WatchGuard Firebox allow malicious code injection

Apache Tika

CVE-2025-54988 is a vulnerability in the tika-parser-pdf-module used for PDF processing in Apache Tika, from version 1.13 through version 3.2.1. It is one of many modules in the broader Tika ecosystem used for data normalization of 1,000 proprietary formats so that software tools can index and read them.

Unfortunately, this same document editing capability makes the software a prime target for campaigns that use XML External Entity (XXE) injection, a recurring issue in this class of tools. In the case of CVE-2025-54988, this could allow an attacker to perform an XXE injection attack by hiding XML Forms Architecture (XFA) instructions within a malicious PDF.

See also: Exploiting vulnerabilities in Sneeit WordPress and ICTBroadcast fuels Frost botnet

Through this, “an attacker may be able to read sensitive data or cause malicious requests to internal resources or third-party servers,” the CVE said. Attackers could exploit the vulnerability to retrieve data from the tool’s document processing chain, extracting it through Tika’s processing of the malicious PDF. Administrators have now realized that the XXE injection vulnerability is not limited to this module.

It affects additional components of Tika, specifically Apache Tika tika-core, versions 1.13 to 3.2.1, and tika-parsers , versions 1.13 to 1.28.5. In addition, older Tika parsers, versions 1.13 to 1.28.5 , are also affected.

Apache Tika: Risk from vulnerability that was fixed months ago

Apache Tika: One vulnerability led to another

This means that there are now two CVEs for the same issue, with the second, CVE-2025-66516, being a superset of the first. Obviously, the reason for issuing a second CVE is to be more cautious. People who fixed CVE-2025-54988 are still at risk due to the additional vulnerabilities reported in CVE-2025-66516.

See also: Intellexa: Exploiting 15 zero-day vulnerabilities since 2021

So far, there is no evidence that the XXE injection vulnerability in these CVEs is being actively exploited by attackers. However, this could change quickly if proof-of-concept exploits. CVE-2025-66516 has been rated the unusual maximum 10.0 in severity, making it a priority for anyone using this software in their environment. Users should update to Tika-core version 3.2.2, tika-parser-pdf-module version 3.2.2 (standalone PDF module), or tika-parsers versions 2.0.0 if they are on an older version.

Apache Tika: Risk from vulnerability that was fixed months ago

However, the fix will only help developers who maintain applications that are known to use Apache Tika. However, in some cases, it may not be referenced in all application configuration files, creating a blind spot where usage is not detected. In this case, the solution would be to disable XML parsing in applications via the tika-config.xml configuration file.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS