Apache Tika developers released fixes for a critical XML External Entity (XXE) vulnerability, tracked as CVE-2025-66516, that can be triggered by a specially crafted XFA file embedded in a PDF. The flaw affects Apache Tika core versions 1.13 through 3.2.1, Apache Tika parsers versions 1.13 through 1.28.5, and the Apache Tika PDF parser module versions 2.0.0 through 3.2.1. The issue is rated CVSS v4 10.0 and could allow attackers to read sensitive files, reach internal network resources, and in worst-case scenarios potentially achieve remote code execution during document processing.
Apache’s advisory says CVE-2025-66516 expands the scope of the earlier CVE-2025-54988, broadening the list of affected artifacts beyond the initial record. Organizations using Tika for content extraction or PDF analysis were urged to upgrade tika-core and tika-parser-pdf-module to version 3.2.2, and tika-parsers to version 2.0.0, as the vulnerable parsing path can be reached through malicious PDF content supplied to downstream applications and services.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
An XML External Entity vulnerability in Apache Tika was initially tracked as CVE-2025-54988. A later Apache notice stated that a subsequent CVE would expand the scope of affected artifacts beyond this earlier record.
Apache Tika developers released security updates to fix the critical XXE vulnerability CVE-2025-66516, which can be triggered via a crafted XFA file embedded in a PDF. Users were advised to update Tika-core and Tika-parser-pdf-module to 3.2.2 and Tika-parsers to 2.0.0.
Apache updated the earlier CVE-2025-54988 to broaden the affected Apache Tika artifacts and tracked the expanded issue as CVE-2025-66516. The expanded scope covered Tika core, Tika parsers, and the Tika PDF parser module.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcecve.org
Open sourcecve.org
Open sourcelists.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.