A critical XML External Entity (XXE) vulnerability, tracked as CVE-2025-66516, has been identified in multiple modules of Apache Tika, including tika-core (versions 1.13–3.2.1), tika-parsers (1.13–1.28.5), and tika-parser-pdf-module (2.0.0–3.2.1). This flaw allows attackers to exploit PDF files containing crafted XFA content to execute XXE attacks, potentially leading to remote code execution or sensitive data exposure. The vulnerability expands upon a previous advisory (CVE-2025-54988) by clarifying that the root issue lies in the core library, not just the PDF parser module, and by broadening the list of affected artifacts to include additional modules and versions.
Security experts emphasize that simply updating the PDF parser module is insufficient; organizations must upgrade the tika-core library to version 3.2.2 or later to fully mitigate the risk. Apache Tika is widely used for document parsing and content extraction across various industries, making this vulnerability particularly impactful. Administrators are advised to review their build configurations (such as Maven or Gradle dependencies) to ensure all vulnerable components are updated, as standard usage of the library is enough to trigger the exploit.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Reference material notes that public proof-of-concept exploits were observed on GitHub, indicating growing security community interest and increasing the likelihood of opportunistic exploitation. No confirmed in-the-wild exploitation was reported in the provided sources.
Maintainers advised users to upgrade tika-core and tika-pdf-module to version 3.2.2 or later, and legacy tika-parsers to 1.28.5 or later, warning that updating only the PDF parser module does not fully remediate the issue. Additional mitigations such as disabling PDF or XML parsing were recommended for exposed environments.
Apache disclosed CVE-2025-66516 as a broader, maximum-severity XXE vulnerability in Apache Tika, clarifying that the root issue resides in tika-core and also affects tika-parsers and the PDF module. The new CVE supersedes or expands on CVE-2025-54988 and raises the severity to CVSS 10.0.
Apache Tika originally disclosed an XML External Entity vulnerability tracked as CVE-2025-54988, affecting PDF processing via malicious PDFs. It was later described as incomplete in scope and remediation, with an earlier severity of 8.4.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
10 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcesecpod.com
Open sourcego.theregister.com
Open sourcecsoonline.com
Open sourcethehackernews.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourceupwind.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.