Tika

Vendor:

First CVE: Dec 15, 2016 · Active for 9 years

25
Total CVEs
More Total CVEs than 95% of tracked products
3.1
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tika over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2016
9 years ago
Most Recent CVE
Dec 4, 2025
232 days ago

CVE Severity & Scoring

Tika25 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local13 (52.0%)
Network12 (48.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (92.0%)
High2 (8.0%)
Unknown0 (0.0%)
User Interaction
None9 (36.0%)
Unknown0 (0.0%)
Required16 (64.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None25 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running
Apr 25, 20188.190NOYES
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML Extern
Dec 4, 20259.887NOYES
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection
Aug 20, 20259.837NONO
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
Jun 16, 20217.534NONO
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a d
Sep 19, 20187.529NONO
A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later.
Aug 2, 20198.828NONO
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 par
Oct 9, 20187.527NONO
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors
Sep 30, 20177.827NONO
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Apr 6, 20179.827NONO
A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.
Dec 24, 20186.525NONO

Exploit Exposure

Signals from CVEs in this product scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.0% of CVEs· 96th percentile
Nuclei
2 CVEs
8.0% of CVEs· 97th percentile
ExploitDB
1 CVE
4.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (25 CVEs).

Media Mentions

Signals from CVEs in this product scope (25 CVEs).

Top CNAs Publishing CVEs For Tika

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.915.36.5%00
1.2517.519.4%00
1.2415.52.5%00
1.1217.83.5%00