← back
CVE-2019-10093

CVE-2019-10093

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 3.7%
exploitation probability
3.7%top 11% of all CVEs
observed exploitation
nono source reports it
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
Affected products
Apache · Apache Tika