Cyber Security News

Critical Apache Tika Core Vulnerability Exploited by Uploading Malicious PDF

A critical security vulnerability in Apache Tika has been discovered that allows attackers to compromise systems by uploading specially crafted PDF files. Organizations worldwide are urged to patch immediately.

Apache Tika is a popular open-source toolkit used by thousands of organizations to extract text and metadata from documents, including PDFs, Word files, and images.

Apache researchers have identified a critical flaw that attackers can exploit by embedding malicious code inside PDF files.

Apache Tika Core Vulnerability

The vulnerability is caused by an XML External Entity (XXE) injection flaw. Attackers create PDF documents containing crafted XFA (XML Forms Architecture) files that trigger the vulnerability when Tika processes them.

This allows attackers to execute arbitrary code, steal sensitive information, or gain unauthorized access to systems.

The vulnerability affects three Apache Tika components across all operating systems:

FieldValue
CVE IDCVE-2025-66516
CVSS Score9.8 (Critical)
Vulnerability TypeXML External Entity (XXE) Injection
Attack VectorMalicious XFA files embedded in PDF documents
Affected PlatformsAll (Windows, Linux, macOS)

Tika-core: Versions 1.13 through 3.2.1 are vulnerable. This is the core library containing the actual flaw.

Tika-parsers: Versions 1.13 before 2.0.0 are affected. This older module contained the PDF parser functionality.

Tika PDF parser module: Versions 2.0.0 through 3.2.1 are vulnerable. This is the newer dedicated PDF component. This vulnerability expands beyond the original CVE-2025-54988 in critical ways.

First, while the vulnerability appeared to be related to the PDF parser module, the actual flaw lies in Tika-core. Organizations that only updated the PDF parser without upgrading Tika-core remain vulnerable to attack.

Second, the original report overlooked that older Tika 1.x releases packaged the PDF parser in the “tika-parsers” module rather than as a separate component.

This means legacy systems could be vulnerable even if users believed they had patched the issue. Immediate action is required: Upgrade Tika-core to version 3.2.2 or later. This single update addresses the vulnerability across all components.

Apache advises organizations using older 1.x versions to contact your software vendor immediately for patched releases. Do not wait for automatic updates.

As a temporary mitigation, restrict PDF file uploads from untrusted external sources until patching is complete.

Organizations that handle sensitive documents, financial records, legal papers, and personal data face an elevated risk from this vulnerability.

Apache Tika maintainers have released fixes, but deployment remains critical. Security teams should prioritize this patch in their vulnerability management processes.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago