CVE-2025-66516

CriticalHigh RiskPatched

Apache Tika XXE Vulnerability

CVSS Score

9.8

Severity

Critical

Available Package Updates

Mavenorg.apache.tika:tika-corev3.2.2View on Maven
Mavenorg.apache.tika:tika-parsersv2.0.0View on Maven
Mavenorg.apache.tika:tika-parser-pdf-modulev3.2.2View on Maven

Fixed in: org.apache.tika:tika-core (Maven): 3.2.2; org.apache.tika:tika-parsers (Maven): 2.0.0; org.apache.tika:tika-parser-pdf-module (Maven): 3.2.2

Exploit Intelligence

Weaponized

Yes

Detectable

Yes

CISA KEV

Not Listed

Risk Level

High Risk

Detection Sources

osv

Exploit Sources

github_poc

Get the Full Explanation

Sign in to get the plain English explanation including what systems are affected, how to fix it, and vendor advisory links.

Published: 12/4/2025