CVE-2025-54988
published 2025-08-20CVE-2025-54988: Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML…
PriorityP351high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
2.96%
85.6th percentile
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| apache | tika | >= 0 < 1.22-2+deb11u1 | 1.22-2+deb11u1 |
| apache | tika | >= 1.13 < 3.2.2 | 3.2.2 |
| apache_software_foundation | apache_tika_core | 1.13 – 3.2.1 | — |
| apache_software_foundation | apache_tika_parsers | >= 1.13 < 2.0.0 | 2.0.0 |
| apache_software_foundation | apache_tika_pdf_parser_module | 2.0.0 – 3.2.1 | — |
| debian | tika | < tika 1.22-2+deb11u1 (bullseye) | tika 1.22-2+deb11u1 (bullseye) |
| ubuntu | tika | — | — |
CVSS provenance
nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.4HIGH
osv8.4HIGH
vendor_oracle9.8HIGH
vendor_apache8.4HIGH
vendor_debian8.4HIGH
vendor_redhat8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Tika vulnerabilities
vendor_ubuntu·2026-05-27
CVE-2025-54988 Apache Tika vulnerabilities
Title: Apache Tika vulnerabilities
Summary: Several security issues were fixed in Apache Tika.
It was discovered that Apache Tika incorrectly handled XML external
entities when parsing XFA content in PDF files. An attacker could possibly
use this issue to obtain sensitive information or send malicious requests
to internal resources or third-party servers.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Oracle Business Rules (Apache Commons Compress) — CVE-2025-54988
vendor_oracle·2026-01-15·CVSS 9.8
CVE-2025-54988 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Oracle Business Rules (Apache Commons Compress) — CVE-2025-54988
Oracle Oracle Fusion Middleware Risk Matrix: Oracle Business Rules (Apache Commons Compress) vulnerability
CVE: CVE-2025-54988
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Red Hat
tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
vendor_redhat·2025-12-04·CVSS 8.4
CVE-2025-66516 [HIGH] CWE-611 tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF.
This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways.
First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2
Red Hat
org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
vendor_redhat·2025-08-20·CVSS 8.4
CVE-2025-54988 [HIGH] CWE-611 org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
An XML External Entity injection flaw was foun
Debian
CVE-2025-66516: tika - Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1...
vendor_debian·2025·CVSS 8.4
CVE-2025-66516 [HIGH] CVE-2025-66516: tika - Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1...
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways. First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable. Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the "org.apache.tika:tika-parsers" module.
Scope: local
Debian
CVE-2025-54988: tika - Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through...
vendor_debian·2025·CVSS 8.4
CVE-2025-54988 [HIGH] CVE-2025-54988: tika - Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through...
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.
Scope: local
bullseye: resolved (fixed in 1.22-2+deb11u1)
sid: open
Apache
Apache tika: CVE-2025-54988
vendor_apache·CVSS 8.4
CVE-2025-54988 [HIGH] Apache tika: CVE-2025-54988
Apache tika: CVE-2025-54988
XXE when parsing XFA via the PDFParser Paras Jain and Yakov Shafranovich of Amazon 1.13-3.2.1
GHSA
Apache Tika has XXE vulnerability
ghsa·2025-12-04·CVSS 8.4
CVE-2025-66516 [HIGH] CWE-611 Apache Tika has XXE vulnerability
Apache Tika has XXE vulnerability
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF.
This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways.
First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable.
Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the "org.apache.t
OSV
Apache Tika has XXE vulnerability
osv·2025-12-04·CVSS 8.4
CVE-2025-66516 [HIGH] Apache Tika has XXE vulnerability
Apache Tika has XXE vulnerability
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF.
This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways.
First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable.
Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the "org.apache.t
OSV
CVE-2025-66516: Critical XXE in Apache Tika tika-core (1
osv·2025-12-04·CVSS 8.4
CVE-2025-66516 [HIGH] CVE-2025-66516: Critical XXE in Apache Tika tika-core (1
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways. First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable. Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the "org.apache.tika:tika-parsers" module.
OSV
CVE-2025-54988: Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1
osv·2025-08-20·CVSS 8.4
CVE-2025-54988 [HIGH] CVE-2025-54988: Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.
GHSA
Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
ghsa·2025-08-20
CVE-2025-54988 [CRITICAL] CWE-611 Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
OSV
Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
osv·2025-08-20
CVE-2025-54988 [CRITICAL] Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
No detection rules found.
No public exploits indexed.
2025-08-20
Published