Apache Tika

Apache · 20 CVEs

CVE-2026-66756
MEDIUM

Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false

Jul 30, 2026

CVE-2026-66755
MEDIUM

Apache Tika: Arbitrary Local File Read in ISArchiveParser

Jul 30, 2026

CVE-2022-33879
LOW

Incomplete fix and new regex DoS in StandardsExtractingContentHandler

Jun 27, 2022

CVE-2022-30973
MEDIUM

Missing fix for CVE-2022-30126 in 1.28.2

May 31, 2022

CVE-2022-30126
MEDIUM

Apache Tika Regular Expression Denial of Service in Standards Extractor

May 16, 2022

CVE-2022-25169
MEDIUM

Apache Tika BPGParser Memory Usage DoS

May 16, 2022

CVE-2021-28657
MEDIUM

Infinite loop in Apache Tika's MP3 parser

Mar 31, 2021

CVE-2020-9489
MEDIUM

tika-core: Denial of Service Vulnerabilities in Some of Apache Tika's Parsers

Apr 27, 2020

CVE-2020-1950
MEDIUM

tika: excessive memory usage in PSDParser

Mar 23, 2020

CVE-2019-10088
HIGH

A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21.…

Aug 2, 2019

CVE-2019-10094
HIGH

A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a S…

Aug 2, 2019

CVE-2019-10093
MEDIUM

In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the po…

Aug 2, 2019

CVE-2018-17197
MEDIUM

tika: Infinite loop in SQLite3Parser resulting in a denial of service

Dec 24, 2018

CVE-2018-11796
HIGH

tika: Incomplete fix allows for XML entity expansion resulting in denial of service

Oct 9, 2018

CVE-2018-8017
MEDIUM

tika: infinite loop in the IptcAnpaParser

Sep 19, 2018

CVE-2018-11762
HIGH

tika: Zip Slip vulnerability in tika-app

Sep 19, 2018

CVE-2018-11761
HIGH

tika: XML entity expansion vulnerability due to lack of limit configuration

Sep 19, 2018

CVE-2018-1339
MEDIUM

tika: Infinite loop in ChmParser can allow remote attacker to cause a denial of service

Apr 25, 2018

CVE-2018-1338
MEDIUM

tika: Infinite loop in BPGParser can allow remote attacker to cause a denial of service

Apr 25, 2018

CVE-2018-1335
HIGH

tika: Command injection in tika-server can allow remote attackers to execute arbitrary commands via crafted headers

Apr 25, 2018

Showing 1 to 20 of 20 CVEs