← Back

Tika

tika

Vendor: Apache • 25 CVEs

CVEs (25)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Tika
Nov 21, 2024
Apr 25, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.
1Apache
1Tika
Nov 21, 2024
Apr 25, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only af...Show more
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.Show less
1Apache
1Tika
May 13, 2026
Sep 30, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML file...Show more
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.Show less
1Apache
2Nutch
Tika
May 13, 2026
Apr 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
1Apache
1Tika
May 6, 2026
Dec 15, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.