ThreatCluster

Apache Tika Toolkit Faces Critical 10.0-Rated Vulnerability

First seen 8 Dec 2025, 02:50 UTC Theregister 97% similarity 34

Article Content

Browse articles
ThreatCluster

The Apache Foundation has issued a warning regarding a critical 10.0-rated vulnerability in its Tika toolkit, which is used for metadata extraction from over 1,000 file formats. This follows a previously reported 8.4-rated flaw (CVE-2025-54988) that allowed XML External Entity injection via crafted XFA files in PDFs. The new vulnerability is identified as CVE-2025-66516.

ThreatCluster AI

Community

Browse all →