Apache Tika Toolkit Faces Critical 10.0-Rated Vulnerability
First seen 8 Dec 2025, 02:50 UTC
•
•97% similarity
•34
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Apache Foundation has issued a warning regarding a critical 10.0-rated vulnerability in its Tika toolkit, which is used for metadata extraction from over 1,000 file formats. This follows a previously reported 8.4-rated flaw (CVE-2025-54988) that allowed XML External Entity injection via crafted XFA files in PDFs. The new vulnerability is identified as CVE-2025-66516.
ThreatCluster AI