Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
Patch soon. It has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apache Tika fails to safely process PDF files containing malicious XML data, allowing attackers to read sensitive files or execute commands on affected systems. This flaw affects multiple Tika components across different versions.
XXE (XML External Entity) injection vulnerability in Apache Tika's PDF parsing logic triggered via crafted XFA (XML Forms Architecture) content within PDF files. Exploitation requires only a specially crafted PDF file and no authentication; impact includes arbitrary file disclosure and potential remote code execution. The vulnerability persists in tika-core across versions 1.13-3.2.1 even if tika-pdf-module is patched, and affects tika-parsers 1.x releases.