Tika
Vendor:
First CVE: Dec 15, 2016 · Active for 9 years
25
Total CVEs
More Total CVEs than 95% of tracked products
3.1
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tika over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2016
9 years ago
Most Recent CVE
Dec 4, 2025
232 days ago
CVE Severity & Scoring
Tika25 CVEs
56%
28%
12%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local13 (52.0%)
Network12 (48.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (92.0%)
High2 (8.0%)
Unknown0 (0.0%)
User Interaction
None9 (36.0%)
Unknown0 (0.0%)
Required16 (64.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None25 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1335HIGH From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running | Apr 25, 2018 | 8.1 | 90 | NO | YES |
CVE-2025-66516CRITICAL Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML Extern | Dec 4, 2025 | 9.8 | 87 | NO | YES |
CVE-2025-54988CRITICAL Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection | Aug 20, 2025 | 9.8 | 37 | NO | NO |
CVE-2021-33813HIGH An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. | Jun 16, 2021 | 7.5 | 34 | NO | NO |
CVE-2018-11761HIGH In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a d | Sep 19, 2018 | 7.5 | 29 | NO | NO |
CVE-2019-10088HIGH A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later. | Aug 2, 2019 | 8.8 | 28 | NO | NO |
CVE-2018-11796HIGH In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 par | Oct 9, 2018 | 7.5 | 27 | NO | NO |
CVE-2016-4434HIGH Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors | Sep 30, 2017 | 7.8 | 27 | NO | NO |
CVE-2016-6809CRITICAL Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization. | Apr 6, 2017 | 9.8 | 27 | NO | NO |
CVE-2018-17197MEDIUM A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika. | Dec 24, 2018 | 6.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.0% of CVEs· 96th percentile
Nuclei
2 CVEs
8.0% of CVEs· 97th percentile
ExploitDB
1 CVE
4.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Tika
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.9 | 1 | 5.3 | 6.5% | 0 | 0 |
| 1.25 | 1 | 7.5 | 19.4% | 0 | 0 |
| 1.24 | 1 | 5.5 | 2.5% | 0 | 0 |
| 1.12 | 1 | 7.8 | 3.5% | 0 | 0 |