← Back

Tika

tika

Vendor: Apache • 25 CVEs

CVEs (25)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Tika
Dec 30, 2025
Dec 4, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA fi...Show more
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways. First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable. Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the "org.apache.tika:tika-parsers" module.Show less
1Apache
1Tika
Nov 4, 2025
Aug 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF....Show more
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.Show less
1Apache
1Tika
Nov 21, 2024
Jun 27, 2022
N/A· v4
3.3 LOW· v3
2.6 LOW· v2
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContent...Show more
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.Show less
1Apache
1Tika
Nov 21, 2024
May 31, 2022
N/A· v4
5.5 MEDIUM· v3
2.6 LOW· v2
We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial...Show more
We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.3.Show less
2Apache
Oracle
2Primavera Unifier
Tika
Nov 21, 2024
May 16, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users...Show more
In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0Show less
2Apache
Oracle
2Primavera Unifier
Tika
Nov 21, 2024
May 16, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.
5Apache
DebianFedoraproject+2 more
6Communications Messaging Server
Debian LinuxFedora+3 more
Nov 21, 2024
Jun 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
2Apache
Oracle
5Communications Messaging Server
Healthcare FoundationPrimavera Unifier+2 more
Nov 21, 2024
Mar 31, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
2Apache
Oracle
5Communications Messaging Server
Flexcube Private BankingPrimavera Unifier+2 more
Nov 21, 2024
Apr 27, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS...Show more
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later. The vulnerabilities in the MP4Parser were partially fixed by upgrading the com.googlecode:isoparser:1.1.22 dependency to org.tallison:isoparser:1.9.41.2. For unrelated security reasons, we upgraded org.apache.cxf to 3.3.6 as part of the 1.24.1 release.Show less
4Apache
CanonicalDebian+1 more
6Business Process Management Suite
Communications Messaging ServerDebian Linux+3 more
Nov 21, 2024
Mar 23, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
4Apache
CanonicalDebian+1 more
6Business Process Management Suite
Communications Messaging ServerDebian Linux+3 more
Nov 21, 2024
Mar 23, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
1Apache
1Tika
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users sho...Show more
A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users should upgrade to 1.22 or later.Show less
1Apache
1Tika
Nov 21, 2024
Aug 2, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
1Apache
1Tika
Nov 21, 2024
Aug 2, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later.
1Apache
1Tika
Nov 21, 2024
Dec 24, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.
1Apache
1Tika
Nov 21, 2024
Oct 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes...Show more
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and thus removes entity expansion limits after the first parse. Apache Tika versions from 0.1 to 1.19 are therefore still vulnerable to entity expansions which can lead to a denial of service attack. Users should upgrade to 1.19.1 or later.Show less
1Apache
1Tika
Nov 21, 2024
Sep 19, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
1Apache
1Tika
Nov 21, 2024
Sep 19, 2018
N/A· v4
5.9 MEDIUM· v3
5.8 MEDIUM· v2
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat",...Show more
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.Show less
2Apache
Oracle
2Business Process Management Suite
Tika
Nov 21, 2024
Sep 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
1Apache
1Tika
Nov 21, 2024
Apr 25, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.