{"id":"GHSA-f58c-gq56-vjjf","summary":"Apache Tika has XXE vulnerability","details":"Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. \n\nThis CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways. \n\nFirst, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to \u003e= 3.2.2 would still be vulnerable. \n\nSecond, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the \"org.apache.tika:tika-parsers\" module.","aliases":["CVE-2025-66516"],"modified":"2025-12-05T02:41:13.387654Z","published":"2025-12-04T18:30:54Z","database_specific":{"cwe_ids":["CWE-611"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2025-12-05T02:24:30Z","nvd_published_at":"2025-12-04T17:15:57Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66516"},{"type":"WEB","url":"https://cve.org/CVERecord?id=CVE-2025-54988"},{"type":"PACKAGE","url":"https://github.com/apache/tika"},{"type":"WEB","url":"https://lists.apache.org/thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k"}],"affected":[{"package":{"name":"org.apache.tika:tika-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tika/tika-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.13"},{"fixed":"3.2.2"}]}],"versions":["1.13","1.14","1.15","1.16","1.17","1.18","1.19","1.19.1","1.20","1.21","1.22","1.23","1.24","1.24.1","1.25","1.26","1.27","1.28","1.28.1","1.28.2","1.28.3","1.28.4","1.28.5","2.0.0","2.0.0-ALPHA","2.0.0-BETA","2.1.0","2.2.0","2.2.1","2.3.0","2.4.0","2.4.1","2.5.0","2.6.0","2.7.0","2.8.0","2.9.0","2.9.1","2.9.2","2.9.3","2.9.4","3.0.0","3.0.0-BETA","3.0.0-BETA2","3.1.0","3.2.0","3.2.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.2.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-f58c-gq56-vjjf/GHSA-f58c-gq56-vjjf.json"}},{"package":{"name":"org.apache.tika:tika-parsers","ecosystem":"Maven","purl":"pkg:maven/org.apache.tika/tika-parsers"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.13"},{"fixed":"2.0.0"}]}],"versions":["1.13","1.14","1.15","1.16","1.17","1.18","1.19","1.19.1","1.20","1.21","1.22","1.23","1.24","1.24.1","1.25","1.26","1.27","1.28","1.28.1","1.28.2","1.28.3","1.28.4","1.28.5","2.0.0-ALPHA","2.0.0-BETA"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-f58c-gq56-vjjf/GHSA-f58c-gq56-vjjf.json"}},{"package":{"name":"org.apache.tika:tika-parser-pdf-module","ecosystem":"Maven","purl":"pkg:maven/org.apache.tika/tika-parser-pdf-module"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"3.2.2"}]}],"versions":["2.0.0","2.1.0","2.2.0","2.2.1","2.3.0","2.4.0","2.4.1","2.5.0","2.6.0","2.7.0","2.8.0","2.9.0","2.9.1","2.9.2","2.9.3","2.9.4","3.0.0","3.0.0-BETA","3.0.0-BETA2","3.1.0","3.2.0","3.2.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.2.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-f58c-gq56-vjjf/GHSA-f58c-gq56-vjjf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}