Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-66516

87
FAUCET Score

CVE-2025-66516 is a critical XML External Entity (XXE) injection vulnerability in Apache Tika's tika-core, tika-pdf-module (versions 2.0.0-3.2.1), and tika-parsers (versions 1.13-1.28.5) modules, allowing attackers to execute arbitrary code via crafted XFA files embedded in PDFs. This vulnerability, a broader scope of CVE-2025-54988, affects users who did not upgrade tika-core to version 3.2.2 or higher, even if other modules were updated. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score is 98/100, and it has garnered significant community discussion and media coverage, indicating high awareness. While not yet listed in the KEV catalog, Nuclei templates for this XXE injection exist, suggesting potential for exploitation. The high level of community discussion and media coverage, including mentions by Atlassian, GitLab, and Oracle, highlights the urgency for patching this critical flaw.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.13, < 3.2.2CPE matchmatch criteria
cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.4HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.5
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
79.81%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2025-66516 · Jan 19, 2026
This CVE's current EPSS score of 0.7981 is in the 98th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

mavenpatch availablevia ghsa
Product: org.apache.tika:tika-coreFixed in: 3.2.2
mavenpatch availablevia ghsa
Product: org.apache.tika:tika-parsersFixed in: 2.0.0
mavenpatch availablevia ghsa
Product: org.apache.tika:tika-parser-pdf-moduleFixed in: 3.2.2
redhatpatch availablevia redhat_api
Product: Red Hat build of Apache Camel 4.14.2 for Spring Boot 3.5.8Fixed in: tika-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.25Fixed in: devspaces/openvsx-rhel9:sha256:5b136fff0f0c8ff4d56fdb934eef1dd7d04ebdac13e7cb8c1e020bf370f4df84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.25Fixed in: devspaces/pluginregistry-rhel9:sha256:fb455374d650d93bbc4eca5616d041067cf1bcebc0dd6d0a92d8af16e2656708
View patch
ubuntupatch availablevia ubuntu_usn
Product: tika (focal)Fixed in: 1.22-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: tika (jammy)Fixed in: 1.22-2+deb11u1build0.22.04.1

Vendor Advisories (3)

ubuntuUSN-8324-1

Apache Tika vulnerabilities

May 27, 2026
mavenGHSA-f58c-gq56-vjjfcritical

Apache Tika has XXE vulnerability

Dec 4, 2025
redhatCVE-2025-66516Critical

tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected

Dec 4, 2025

References

cve.org / CVERecord
Third Party Advisory
lists.apache.org / thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k
Vendor Advisory