Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-11796

27
FAUCET Score

CVE-2018-11796 is a denial-of-service vulnerability affecting Apache Tika versions 0.1 through 1.19. The vulnerability stems from the SAXParser's reset() method removing the entity expansion limit after the initial parse, allowing for XML entity expansion attacks. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low complexity, potentially leading to a complete denial of service. There is currently no public exploit code available, and it is not known to be actively exploited, with minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.1, <= 1.19CPE matchmatch criteria
cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
6.88%
Probability of exploitation in next 30 days
EPSS Percentile
93.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0688 is in the 89th percentile among its peer group of 51,455 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

mavenpatch availablevia ghsa
Product: org.apache.tika:tika-coreFixed in: 1.19.1
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.5.0Fixed in: camel-tika
View patch
redhatend of lifevia redhat_api
Product: Red Hat Satellite 5Fixed in: tika

Vendor Advisories (2)

mavenGHSA-h8q5-g2cj-qr5hhigh

Apache Tika is vulnerable to entity expansions which can lead to a denial of service attack

Oct 17, 2018
redhatCVE-2018-11796Moderate

tika: Incomplete fix allows for XML entity expansion resulting in denial of service

Oct 10, 2018

References

access.redhat.com / errata/RHSA-2019:3892
lists.apache.org / thread.html/88de8350cda9b184888ec294c813c5bd8a2081de8fd3666f8904bc05%40%3Cdev.tika.apache.org%3E
security.netapp.com / advisory/ntap-20190903-0002
securityfocus.com / bid/105585
Third Party AdvisoryVDB Entry