CVE-2025-66516Disclosure(apache / tika)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache tika systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways. First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable. Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the "org.apache.tika:tika-parsers" module.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tika

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-14); latest day: 1
  • 8 total mentions across 7 days

Affected systems

Vendors
Products
tika

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-02-02: 1Mentions · 2026-02-13: 1Mentions · 2026-02-23: 1Mentions · 2026-03-14: 2Mentions · 2026-07-22: 1Mentions · 2026-07-31: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-03-14: 1PoC Mentioned / Linked · 2026-07-31: 1Exploit Tool / Code · 2026-07-31: 1Exploit Tool / Code · 2026-09-11: 1Patch / Workaround · 2026-03-14: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-13: 1Technical Details · 2026-03-14: 2Technical Details · 2026-07-22: 1Technical Details · 2026-07-31: 1Technical Details · 2026-09-11: 102-0202-1302-2303-1407-2207-3109-11
Signal classification4 categories
Disclosure
337.5%
General
225.0%
Exploit
225.0%
Patch
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-021
General1
2026-02-131
Disclosure1
2026-02-231
General1
2026-03-142
Disclosure1Patch1
2026-07-221
Disclosure1
2026-07-311
Exploit1
2026-09-111
Exploit1
Full discourse8 posts
  • kmkz@kmkz_security
    Exploit

    Back from mission, I released the exploit I used (it was really helpful) for #Apache Tika XFA XXE exposed through #Elasticsearch’s attachment ingest processor, leading to arbitrary file read: CVE-2025-54988 / CVE-2025-66516 - Python PoC - version-aware Metasploit module (loot storage, automatic cleanup + no index or document creation) https://github.com/kmkz/Exploits/tree/master/2026/CVE-2025-54988-Elasticsearch-Tika-XFA-XXE @metasploit PR done: https://github.com/rapid7/metasploit-framework/pull/21739

    Post summary

    The author released a Python PoC and a Metasploit module for CVE-2025-54988/CVE-2025-66516, detailing an XXE flaw in Elasticsearch’s Tika attachment processor that allows arbitrary file reads, with code available on GitHub.

    0402052.6K
    19.8K followersView on X
  • Kaan@wkaandemir
    General

    Güvenlik Rehberi'ne taze güncelleme! 🔥 Artık repo OWASP Top 10 2025'le sınırlı değil; her ay yeni açıklar, tehditler ve pratik çözümlerle genişleyecek. Bu ay: OWASP notlarını detaylandırdım + şu açıkları ekledim: • Windows DWM info leak (CVE-2026-20805) • Windows Graphics EoP (CVE-2026-20822) • Linux mlx5e UAF (CVE-2026-23000) • Cisco CM RCE (CVE-2026-20045) • Apache Tika XXE (CVE-2025-66516) Yeni dokümanlar, checklist'ler ve önerilerle daha güçlü.

    Post summary

    The update announces new CVEs added to a security guide, providing basic vulnerability type details but no PoC, exploit code, active exploitation evidence, patches, or debunking information.

    11061500
    1.8K followersView on X
  • OPSWAT@OPSWAT
    Disclosure

    A critical XXE vulnerability in Apache Tika (CVE-2025-66516) shows why patching alone is no longer enough. Learn how file sanitization, behavioral analysis, and software supply chain security work together to reduce risk when trusted libraries fail. Read the analysis. https://bit.ly/4rVO9Ud

    Post summary

    The post announces a critical XXE flaw (CVE‑2025‑66516) in Apache Tika, emphasizing that patching alone is insufficient and advocating for additional safeguards such as file sanitization and supply‑chain security.

    0002096
    7.2K followersView on X
  • Picus Security@PicusSecurity
    Patch

    CVE-2025-66516 in Apache Tika. CVSS 8.4. The root cause is in tika-core, not the PDF parser. Upgrading the wrong module won't fix it. Attack path: malicious XFA in a PDF → XXE → local file disclosure. Fix: tika-core 3.2.2+ Simulate it in Picus with Threat ID 74403. Full breakdown: https://hubs.li/Q046G6SK0 #CVE202566516 #XXE

    Post summary

    CVE-2025-66516 is a high‑severity XXE flaw in Apache Tika’s tika-core; patching to version 3.2.2+ resolves the issue, and technical details with a PoC are available via the linked breakdown.

    00010286
    2.9K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Exploit

    🔒 #CyberSecurity CVE-2025-66516: Apache Tika XXE in Elasticsearch Ingest-Attachment — Detection … "Rapid7's latest Metasploit wrap-up landed with sixteen new modules — and for defenders,…" 🔗 https://securityarsenal.com/blog/cve-2025-66516-apache-tika-xxe-in-elasticsearch-ingest-attachment-detection-and-remediation-guide #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    Post summary

    Rapid7 has released 16 new Metasploit modules targeting CVE‑2025‑66516, an Apache Tika XXE flaw in Elasticsearch ingest‑attachment, but no evidence of current exploitation in the wild is presented.

    0000080
    31 followersView on X
  • @pedri77@pedri77
    Disclosure

    A critical security flaw has been disclosed in Apache Tika that could result in an XML external entity (XXE) injection attack. The vulnerability, tracked as CVE-2025-66516, is rated 10.0 on the CVSS scoring scale, indic... https://f.mtr.cool/oahidflmkl

    Post summary

    The post announces the discovery of a critical Apache Tika vulnerability (CVE-2025-66516) that can exploit XML external entity injection, with a maximum CVSS score of 10.0.

    0000047
    2.1K followersView on X
  • Sarath Reddy@Sarath802274020
    Disclosure

    “CVE-2025–66516 & 54988: Breaking Apache Tika with Malicious PDFs” by Sarath Reddy https://systemweakness.com/cve-2025-66516-54988-breaking-apache-tika-with-malicious-pdfs-45b01e3f50ba https://t.co/txRvYaY3Re

    Post summary

    The tweet announces the disclosure of two CVEs that allow malicious PDFs to break Apache Tika, pointing to an article that likely details the vulnerability.

    00000190
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Atlassian ❗ CVE-2025-9288 ❗ CVE-2025-9287 ❗ CVE-2025-66516 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-atlassian-2/ https://t.co/l0dkYooFAV

    Post summary

    The post lists three Atlassian CVEs and directs readers to a link for additional information, but provides no further technical or operational details.

    00000169
    6.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetika---

Explore more