CVE-2025-66516 is a critical XML External Entity (XXE) injection vulnerability in Apache Tika's tika-core, tika-pdf-module (versions 2.0.0-3.2.1), and tika-parsers (versions 1.13-1.28.5) modules, allowing attackers to execute arbitrary code via crafted XFA files embedded in PDFs. This vulnerability, a broader scope of CVE-2025-54988, affects users who did not upgrade tika-core to version 3.2.2 or higher, even if other modules were updated. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score is 98/100, and it has garnered significant community discussion and media coverage, indicating high awareness. While not yet listed in the KEV catalog, Nuclei templates for this XXE injection exist, suggesting potential for exploitation. The high level of community discussion and media coverage, including mentions by Atlassian, GitLab, and Oracle, highlights the urgency for patching this critical flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.13, < 3.2.2CPE matchmatch criteria | cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Tika vulnerabilities
May 27, 2026Apache Tika has XXE vulnerability
Dec 4, 2025tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
Dec 4, 2025