← Vulnerability feed

Vulnerability record · CVE-2025-66516 · published 4 December 2025

CVE-2025-66516: Apache Tika XXE via crafted XFA file in PDF

Apache · Tika

Apache Tika's tika-core, tika-pdf-module and tika-parsers modules are vulnerable to XML External Entity injection when parsing a crafted XFA file embedded in a PDF. This CVE expands the scope of CVE-2025-54988: the flaw and its fix live in tika-core, so upgrading only the PDF module leaves users exposed, and 1.x releases carry the PDFParser in tika-parsers. It matters because Tika is widely embedded in ingestion pipelines, so untrusted documents can trigger the flaw without any user action.

9.8 CVSS 3.1 Critical EPSS 88% · top 0.2% CWE-611 · XML external entity (XXE)
9.8CVSS 3.1 base score
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways. First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable. Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the "org.apache.tika:tika-parsers" module.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and a very high EPSS score make this a top remediation priority despite no KEV listing.

What it is

Apache Tika's tika-core, tika-pdf-module and tika-parsers modules are vulnerable to XML External Entity injection when parsing a crafted XFA file embedded in a PDF. This CVE expands the scope of CVE-2025-54988: the flaw and its fix live in tika-core, so upgrading only the PDF module leaves users exposed, and 1.x releases carry the PDFParser in tika-parsers. It matters because Tika is widely embedded in ingestion pipelines, so untrusted documents can trigger the flaw without any user action.

Impact

An attacker can cause the parser to resolve external entities, leading to disclosure of local files or server-side request forgery, and the CVSS vector also rates high integrity and availability impact. In practice this gives an unauthenticated attacker a path to read data and disrupt the parsing service.

Attack surface

Reached remotely over the network by submitting a malicious PDF containing a crafted XFA file to any service that uses Tika for document parsing. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV and no public exploit reference is tagged, but EPSS is very high at 0.877 (99.75th percentile), indicating elevated near-term exploitation likelihood. Reference tags are only vendor and third-party advisories, so no confirmed in-the-wild exploitation is documented here.

What to do

  • Upgrade tika-core to 3.2.2 or later; upgrading only tika-pdf-module is insufficient.
  • For 1.x deployments, upgrade tika-parsers to a fixed release, since the PDFParser lives there in that line.
  • Disable external entity and DTD processing in the XML parser configuration used for XFA and other untrusted XML.
  • Isolate or sandbox Tika parsing services and restrict outbound network access to limit SSRF and file-read impact.
  • Treat all uploaded PDFs as untrusted and validate or reject documents with XFA content where XFA is not required.

Detection

  • Monitor Tika parsing logs for XML parser errors, entity resolution failures or unexpected external fetches during PDF processing.
  • Alert on outbound network connections from Tika hosts to unusual destinations, which may indicate SSRF via external entities.
  • Inspect uploaded PDFs for XFA streams and flag documents containing XFA for additional review.
  • Track file access on Tika hosts for reads of sensitive local files outside expected document paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-66516 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-6809Apache nutch deserialization of untrusted data vulnerabilityApache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to d…EPSS 8.0%8.8CVE-2019-10088Apache tika allocation without limits vulnerabilityA carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 o…EPSS 4.8%8.4CVE-2025-54988Apache tika xml external entity (xxe) vulnerabilityCritical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out…EPSS 38%8.1CVE-2018-1335Apache Tika tika-server header command injectionApache Tika versions 1.7 through 1.17 allow clients to send crafted headers to tika-server that are injected into the server's command line, enabling…EPSS 94%analysed7.8CVE-2019-10094Apache tika allocation without limits vulnerabilityA carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Ti…EPSS 2.5%7.8CVE-2016-4434Apache tika xml external entity (xxe) vulnerabilityApache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External En…EPSS 3.6%7.5CVE-2021-33813Jdom xml external entity (xxe) vulnerabilityAn XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.EPSS 19%7.5CVE-2018-11796Apache tika xml external entity (xxe) vulnerabilityIn Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after eac…EPSS 6.9%

Source: NIST National Vulnerability Database (record CVE-2025-66516), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.