CVE-2025-54988 is a critical XML External Entity (XXE) injection vulnerability in Apache Tika's tika-parser-pdf-module, affecting versions 1.13 through 3.2.1. An unauthenticated attacker can exploit this flaw by submitting a crafted XFA file within a PDF, potentially leading to sensitive data disclosure or malicious requests to internal/external resources. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network with no user interaction, allowing for complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media attention, indicating a high level of awareness. Users are strongly advised to upgrade to Apache Tika version 3.2.2 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.13, < 3.2.2CPE matchmatch criteria | cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Tika vulnerabilities
May 27, 2026Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
Aug 20, 2025org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
Aug 20, 2025