CVE-2026-66756
- EPSS 0.45%
- Veröffentlicht 30.07.2026 19:18:07
- Zuletzt bearbeitet 10.08.2026 14:15:32
Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
CVE-2026-66755
- EPSS 0.44%
- Veröffentlicht 30.07.2026 19:16:42
- Zuletzt bearbeitet 01.09.2026 13:19:55
Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files ...
CVE-2025-66516
- EPSS 78.79%
- Veröffentlicht 04.12.2025 16:17:24
- Zuletzt bearbeitet 30.12.2025 16:15:46
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE...
CVE-2025-54988
- EPSS 9.09%
- Veröffentlicht 20.08.2025 20:15:33
- Zuletzt bearbeitet 04.11.2025 22:16:29
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to rea...
CVE-2022-33879
- EPSS 1.91%
- Veröffentlicht 27.06.2022 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:08:30
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed i...
CVE-2022-30973
- EPSS 1.99%
- Veröffentlicht 31.05.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 07:03:39
We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtrac...
CVE-2022-30126
- EPSS 2.61%
- Veröffentlicht 16.05.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:02:12
In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the Standards...
CVE-2022-25169
- EPSS 2.12%
- Veröffentlicht 16.05.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:44
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.
CVE-2021-33813
- EPSS 19.44%
- Veröffentlicht 16.06.2021 12:15:12
- Zuletzt bearbeitet 21.11.2024 06:09:37
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
CVE-2021-28657
- EPSS 2.75%
- Veröffentlicht 31.03.2021 08:15:11
- Zuletzt bearbeitet 21.11.2024 06:00:02
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.