CVE-2025-66516: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66516?
CVE-2025-66516 is classified as a critical severity vulnerability due to its potential for XML External Entity injection.
How do I fix CVE-2025-66516?
To fix CVE-2025-66516, upgrade to the latest version of Apache Tika or its related modules that address this vulnerability.
What components are affected by CVE-2025-66516?
CVE-2025-66516 affects the Apache Tika core, Tika PDF Parser Module, and Tika Parsers across specified versions.
Can CVE-2025-66516 be exploited on all platforms?
Yes, CVE-2025-66516 can be exploited on all platforms where the affected Apache Tika components are used.
What type of attack is enabled by CVE-2025-66516?
CVE-2025-66516 allows attackers to carry out XML External Entity injection via crafted XFA files inside PDFs.