Back Linuxsecurity Ubuntu Apache Tika Important Info Exposure USN-8717-1 CVE-2026
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
Apache Tika could be made to expose sensitive information over the network. Software Description: - tika: A content analysis toolkit Details: It was discovered that Apache Tika's ISA-Tab parser incorrectly handled file path resolution. An attacker who could place files in a directory that Tika subsequently parses could use this issue to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output.
Apache Tika could be made to expose sensitive information over the
Software Description:
- tika: A content analysis toolkit
It was discovered that Apache Tika's ISA-Tab parser incorrectly handled
file path resolution. An attacker who could place files in a directory that
Tika subsequently parses could use this issue to read arbitrary files
accessible to the Tika process and have their contents emitted into the
extracted text output.
The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libtika-java 1.22-2+deb11u1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS libtika-java 1.22-1ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
Ubuntu Security Notice USN-8717-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
