Bug 2418870 (CVE-2025-66516) - CVE-2025-66516 tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
Summary: CVE-2025-66516 tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika c...
Keywords:
Status: NEW
Alias: CVE-2025-66516
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-12-04 17:02 UTC by OSIDB Bzimport
Modified: 2025-12-19 18:23 UTC (History)
30 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:23143 0 None None None 2025-12-11 20:15:39 UTC

Description OSIDB Bzimport 2025-12-04 17:02:16 UTC
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. 

This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways. 

First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable. 

Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the "org.apache.tika:tika-parsers" module.

Comment 4 errata-xmlrpc 2025-12-11 20:15:36 UTC
This issue has been addressed in the following products:

  Red Hat build of Apache Camel 4.14.2 for Spring Boot 3.5.8

Via RHSA-2025:23143 https://access.redhat.com/errata/RHSA-2025:23143


Note You need to log in before you can comment on or make changes to this bug.