Infosec in Brief The Apache Foundation last week warned of a 10.0-rated flaw in its Tika toolkit.

Tika detects and extracts metadata from over 1,000 different file formats. Last August, Apache reported CVE-2025-54988, an 8.4 rated flaw that it warned allows an attacker to carry out XML External Entity injection via a crafted XFA file inside a PDF.

Apache fixed that flaw but last Friday announced a related, and worse, problem known as CVE-2025-66516.

As Apache explained, the entry point for CVE-2025-54988 was Tika’s tika-parser-pdf-module, but the vulnerability and its fix were in another piece of code called `ti…

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help