Apache / Tika
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-66756 | Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false | MEDIUM | 6.9 | Jul 30, 2026 |
| CVE-2026-66755 | Apache Tika: Arbitrary Local File Read in ISArchiveParser | MEDIUM | 5.9 | Jul 30, 2026 |
| CVE-2025-66516 | Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected | CRITICAL | 10.0 | Dec 4, 2025 |
| CVE-2025-54988 | Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA | CRITICAL | 9.3 | Aug 20, 2025 |
| CVE-2022-33879 | Incomplete fix and new regex DoS in StandardsExtractingContentHandler | LOW | 3.3 | Jun 27, 2022 |
| CVE-2022-30973 | Missing fix for CVE-2022-30126 in 1.28.2 | MEDIUM | 5.5 | May 31, 2022 |
| CVE-2022-30126 | Apache Tika Regular Expression Denial of Service in Standards Extractor | MEDIUM | 5.5 | May 16, 2022 |
| CVE-2022-25169 | Apache Tika BPGParser Memory Usage DoS | MEDIUM | 5.5 | May 16, 2022 |
| CVE-2021-33813 | jdom: XXE allows attackers to cause a DoS via a crafted HTTP request | HIGH | 7.5 | Jun 16, 2021 |
| CVE-2021-28657 | Infinite loop in Apache Tika's MP3 parser | MEDIUM | 5.5 | Mar 31, 2021 |
| CVE-2020-9489 | tika-core: Denial of Service Vulnerabilities in Some of Apache Tika's Parsers | MEDIUM | 5.5 | Apr 27, 2020 |
| CVE-2020-1951 | A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. | MEDIUM | 5.5 | Mar 23, 2020 |
| CVE-2020-1950 | tika: excessive memory usage in PSDParser | MEDIUM | 5.5 | Mar 23, 2020 |
| CVE-2019-10088 | A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later. | HIGH | 8.8 | Aug 2, 2019 |
| CVE-2019-10094 | A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's Recur… | HIGH | 7.8 | Aug 2, 2019 |
| CVE-2019-10093 | In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache T… | MEDIUM | 6.5 | Aug 2, 2019 |
| CVE-2018-17197 | tika: Infinite loop in SQLite3Parser resulting in a denial of service | MEDIUM | 6.5 | Dec 24, 2018 |
| CVE-2018-11796 | tika: Incomplete fix allows for XML entity expansion resulting in denial of service | HIGH | 7.5 | Oct 9, 2018 |
| CVE-2018-8017 | tika: infinite loop in the IptcAnpaParser | MEDIUM | 5.5 | Sep 19, 2018 |
| CVE-2018-11762 | tika: Zip Slip vulnerability in tika-app | HIGH | 7.5 | Sep 19, 2018 |
| CVE-2018-11761 | tika: XML entity expansion vulnerability due to lack of limit configuration | HIGH | 7.5 | Sep 19, 2018 |
| CVE-2018-1339 | tika: Infinite loop in ChmParser can allow remote attacker to cause a denial of service | MEDIUM | 6.5 | Apr 25, 2018 |
| CVE-2018-1338 | tika: Infinite loop in BPGParser can allow remote attacker to cause a denial of service | MEDIUM | 6.5 | Apr 25, 2018 |
| CVE-2018-1335 | tika: Command injection in tika-server can allow remote attackers to execute arbitrary commands via crafted headers | HIGH | 8.8 | Apr 25, 2018 |
| CVE-2016-4434 | tika: XML External Entity vulnerability | HIGH | 7.8 | Sep 29, 2017 |
Showing 1 to 25 of 27 CVEs