Apache Tika
Apache · 20 CVEs
Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
Jul 30, 2026
Apache Tika: Arbitrary Local File Read in ISArchiveParser
Jul 30, 2026
Incomplete fix and new regex DoS in StandardsExtractingContentHandler
Jun 27, 2022
Missing fix for CVE-2022-30126 in 1.28.2
May 31, 2022
Apache Tika Regular Expression Denial of Service in Standards Extractor
May 16, 2022
Apache Tika BPGParser Memory Usage DoS
May 16, 2022
Infinite loop in Apache Tika's MP3 parser
Mar 31, 2021
tika-core: Denial of Service Vulnerabilities in Some of Apache Tika's Parsers
Apr 27, 2020
tika: excessive memory usage in PSDParser
Mar 23, 2020
A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21.…
Aug 2, 2019
A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a S…
Aug 2, 2019
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the po…
Aug 2, 2019
tika: Infinite loop in SQLite3Parser resulting in a denial of service
Dec 24, 2018
tika: Incomplete fix allows for XML entity expansion resulting in denial of service
Oct 9, 2018
tika: infinite loop in the IptcAnpaParser
Sep 19, 2018
tika: Zip Slip vulnerability in tika-app
Sep 19, 2018
tika: XML entity expansion vulnerability due to lack of limit configuration
Sep 19, 2018
tika: Infinite loop in ChmParser can allow remote attacker to cause a denial of service
Apr 25, 2018
tika: Infinite loop in BPGParser can allow remote attacker to cause a denial of service
Apr 25, 2018
tika: Command injection in tika-server can allow remote attackers to execute arbitrary commands via crafted headers
Apr 25, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-66756 | Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false | MEDIUM | 0.75% | Jul 30, 2026 |
| CVE-2026-66755 | Apache Tika: Arbitrary Local File Read in ISArchiveParser | MEDIUM | 0.63% | Jul 30, 2026 |
| CVE-2022-33879 | Incomplete fix and new regex DoS in StandardsExtractingContentHandler | LOW | 1.98% | Jun 27, 2022 |
| CVE-2022-30973 | Missing fix for CVE-2022-30126 in 1.28.2 | MEDIUM | 2.04% | May 31, 2022 |
| CVE-2022-30126 | Apache Tika Regular Expression Denial of Service in Standards Extractor | MEDIUM | 2.61% | May 16, 2022 |
| CVE-2022-25169 | Apache Tika BPGParser Memory Usage DoS | MEDIUM | 2.21% | May 16, 2022 |
| CVE-2021-28657 | Infinite loop in Apache Tika's MP3 parser | MEDIUM | 2.75% | Mar 31, 2021 |
| CVE-2020-9489 | tika-core: Denial of Service Vulnerabilities in Some of Apache Tika's Parsers | MEDIUM | 2.61% | Apr 27, 2020 |
| CVE-2020-1950 | tika: excessive memory usage in PSDParser | MEDIUM | 2.99% | Mar 23, 2020 |
| CVE-2019-10088 | A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later. | HIGH | 4.84% | Aug 2, 2019 |
| CVE-2019-10094 | A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's Recur… | HIGH | 2.46% | Aug 2, 2019 |
| CVE-2019-10093 | In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache T… | MEDIUM | 3.70% | Aug 2, 2019 |
| CVE-2018-17197 | tika: Infinite loop in SQLite3Parser resulting in a denial of service | MEDIUM | 6.15% | Dec 24, 2018 |
| CVE-2018-11796 | tika: Incomplete fix allows for XML entity expansion resulting in denial of service | HIGH | 7.54% | Oct 9, 2018 |
| CVE-2018-8017 | tika: infinite loop in the IptcAnpaParser | MEDIUM | 2.28% | Sep 19, 2018 |
| CVE-2018-11762 | tika: Zip Slip vulnerability in tika-app | HIGH | 5.45% | Sep 19, 2018 |
| CVE-2018-11761 | tika: XML entity expansion vulnerability due to lack of limit configuration | HIGH | 9.38% | Sep 19, 2018 |
| CVE-2018-1339 | tika: Infinite loop in ChmParser can allow remote attacker to cause a denial of service | MEDIUM | 2.56% | Apr 25, 2018 |
| CVE-2018-1338 | tika: Infinite loop in BPGParser can allow remote attacker to cause a denial of service | MEDIUM | 1.92% | Apr 25, 2018 |
| CVE-2018-1335 | tika: Command injection in tika-server can allow remote attackers to execute arbitrary commands via crafted headers | HIGH | 93.55% | Apr 25, 2018 |
Showing 1 to 20 of 20 CVEs