Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
Critical severity
GitHub Reviewed
Published
Aug 20, 2025
to the GitHub Advisory Database
•
Updated Aug 21, 2025
Package
Affected versions
>= 1.13, < 3.2.2
Patched versions
3.2.2
Description
Published by the National Vulnerability Database
Aug 20, 2025
Published to the GitHub Advisory Database
Aug 20, 2025
Reviewed
Aug 21, 2025
Last updated
Aug 21, 2025
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
References