Users are recommended to upgrade to version 3.2.2, which fixes this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4350-1 | tika security update |
EUVD |
EUVD-2025-25435 | Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF |
Github GHSA |
GHSA-p72g-pv48-7w9x | Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF |
Thu, 26 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 02 Sep 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 25 Aug 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:* |
Sun, 24 Aug 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache tika |
|
| Vendors & Products |
Apache
Apache tika |
Thu, 21 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Thu, 21 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 20 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue. | |
| Title | Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA | |
| Weaknesses | CWE-611 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-02-26T17:48:22.169Z
Reserved: 2025-08-04T16:04:26.626Z
Link: CVE-2025-54988
Updated: 2025-11-04T22:06:45.688Z
Status : Modified
Published: 2025-08-20T20:15:33.070
Modified: 2025-11-04T22:16:29.870
Link: CVE-2025-54988
OpenCVE Enrichment
Updated: 2025-08-24T22:19:08Z
Debian DLA
EUVD
Github GHSA