A vulnerability in the widely used tool Apache Tikamay have much more serious vulnerabilities than initially thought, according to the project's administrators. The vulnerability was first disclosed last summer. But a new advisory addresses two related vulnerabilities, CVE-2025-54988 reported in August (severity rating 8.4), and CVE-2025-66516 , reported last week, with a severity rating of 10.
See also: Critical vulnerabilities in WatchGuard Firebox allow malicious code injection

CVE-2025-54988 is a vulnerability in the tika-parser-pdf-module used for PDF processing in Apache Tika, from version 1.13 through version 3.2.1. It is one of many modules in the broader Tika ecosystem used for data normalization of 1,000 proprietary formats so that software tools can index and read them.
Unfortunately, this same document editing capability makes the software a prime target for campaigns that use XML External Entity (XXE) injection, a recurring issue in this class of tools. In the case of CVE-2025-54988, this could allow an attacker to perform an XXE injection attack by hiding XML Forms Architecture (XFA) instructions within a malicious PDF.
See also: Exploiting vulnerabilities in Sneeit WordPress and ICTBroadcast fuels Frost botnet
Through this, “an attacker may be able to read sensitive data or cause malicious requests to internal resources or third-party servers,” the CVE said. Attackers could exploit the vulnerability to retrieve data from the tool’s document processing chain, extracting it through Tika’s processing of the malicious PDF. Administrators have now realized that the XXE injection vulnerability is not limited to this module.
It affects additional components of Tika, specifically Apache Tika tika-core, versions 1.13 to 3.2.1, and tika-parsers , versions 1.13 to 1.28.5. In addition, older Tika parsers, versions 1.13 to 1.28.5 , are also affected.

Apache Tika: One vulnerability led to another
This means that there are now two CVEs for the same issue, with the second, CVE-2025-66516, being a superset of the first. Obviously, the reason for issuing a second CVE is to be more cautious. People who fixed CVE-2025-54988 are still at risk due to the additional vulnerabilities reported in CVE-2025-66516.
See also: Intellexa: Exploiting 15 zero-day vulnerabilities since 2021
So far, there is no evidence that the XXE injection vulnerability in these CVEs is being actively exploited by attackers. However, this could change quickly if proof-of-concept exploits. CVE-2025-66516 has been rated the unusual maximum 10.0 in severity, making it a priority for anyone using this software in their environment. Users should update to Tika-core version 3.2.2, tika-parser-pdf-module version 3.2.2 (standalone PDF module), or tika-parsers versions 2.0.0 if they are on an older version.

However, the fix will only help developers who maintain applications that are known to use Apache Tika. However, in some cases, it may not be referenced in all application configuration files, creating a blind spot where usage is not detected. In this case, the solution would be to disable XML parsing in applications via the tika-config.xml configuration file.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
