Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
CVSS Details
- CVSS 3.1 Base Score: 8.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | Dec 12, 2025 | Dec 11, 2025 |
| Debian | — | Upgrade tika | Oct 28, 2025 | Oct 28, 2025 |
| Red Hat Jboss Eap | — | — | Sep 25, 2025 | Aug 20, 2025 |
| Ubuntu | — | Upgrade libtika-javaUpgrade libtika-java (Ubuntu Pro) | May 28, 2026 | May 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub