{"id":"GHSA-p72g-pv48-7w9x","summary":"Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF","details":"Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard.\n\nUsers are recommended to upgrade to version 3.2.2, which fixes this issue.","aliases":["CVE-2025-54988"],"modified":"2026-07-17T21:05:26.238366610Z","published":"2025-08-20T21:30:27Z","database_specific":{"cwe_ids":["CWE-611"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2025-08-21T14:36:27Z","nvd_published_at":"2025-08-20T20:15:33Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54988"},{"type":"WEB","url":"https://github.com/apache/tika/pull/2291"},{"type":"WEB","url":"https://github.com/apache/tika/commit/2b52257304f4d3cde2b8463657380bdb936d9ef2"},{"type":"WEB","url":"https://archive.apache.org/dist/tika/3.2.2/CHANGES-3.2.2.txt"},{"type":"PACKAGE","url":"https://github.com/apache/tika"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/TIKA-4459"},{"type":"WEB","url":"https://lists.apache.org/thread/8xn3rqy6kz5b3l1t83kcofkw0w4mmj1w"},{"type":"WEB","url":"https://lists.apache.org/thread/stn9oh7rfn9yv76n1srxr9w56oy04p72"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00030.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/08/20/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/08/20/3"}],"affected":[{"package":{"name":"org.apache.tika:tika-parser-pdf-module","ecosystem":"Maven","purl":"pkg:maven/org.apache.tika/tika-parser-pdf-module"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.13"},{"fixed":"3.2.2"}]}],"versions":["2.0.0","2.0.0-ALPHA","2.0.0-BETA","2.1.0","2.2.0","2.2.1","2.3.0","2.4.0","2.4.1","2.5.0","2.6.0","2.7.0","2.8.0","2.9.0","2.9.1","2.9.2","2.9.3","2.9.4","3.0.0","3.0.0-BETA","3.0.0-BETA2","3.1.0","3.2.0","3.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-p72g-pv48-7w9x/GHSA-p72g-pv48-7w9x.json"}},{"package":{"name":"org.apache.tika:tika-parsers","ecosystem":"Maven","purl":"pkg:maven/org.apache.tika/tika-parsers"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.13"},{"fixed":"2.0.0-ALPHA"}]}],"versions":["1.13","1.14","1.15","1.16","1.17","1.18","1.19","1.19.1","1.20","1.21","1.22","1.23","1.24","1.24.1","1.25","1.26","1.27","1.28","1.28.1","1.28.2","1.28.3","1.28.4","1.28.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-p72g-pv48-7w9x/GHSA-p72g-pv48-7w9x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}