Skip to content

Update org.apache.tika:tika-core to v3 (release/9.3)#10108

Merged
nielsm5 merged 1 commit intorelease/9.3from
renovate/release/9.3-maven-org.apache.tika-tika-core-vulnerability
Dec 7, 2025
Merged

Update org.apache.tika:tika-core to v3 (release/9.3)#10108
nielsm5 merged 1 commit intorelease/9.3from
renovate/release/9.3-maven-org.apache.tika-tika-core-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Dec 7, 2025

This PR contains the following updates:

Package Change Age Confidence
org.apache.tika:tika-core (source) 2.9.4 -> 3.2.3 age confidence

Apache Tika has XXE vulnerability

CVE-2025-66516 / GHSA-f58c-gq56-vjjf

More information

Details

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF.

This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways.

First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable.

Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the "org.apache.tika:tika-parsers" module.

Severity

  • CVSS Score: 10.0 / 10 (Critical)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

apache/tika (org.apache.tika:tika-core)

v3.2.3

Compare Source

v3.2.2

Compare Source

v3.2.1

Compare Source

v3.2.0

Compare Source

v3.1.0

Compare Source

v3.0.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added 9.3 CVE Dependencies Pull requests that update a dependency file labels Dec 7, 2025
@renovate renovate bot requested a review from a team as a code owner December 7, 2025 19:10
@renovate renovate bot added the Security label Dec 7, 2025
@sonarqubecloud
Copy link

sonarqubecloud bot commented Dec 7, 2025

@nielsm5 nielsm5 merged commit f2e9f32 into release/9.3 Dec 7, 2025
27 checks passed
@nielsm5 nielsm5 deleted the renovate/release/9.3-maven-org.apache.tika-tika-core-vulnerability branch December 7, 2025 20:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

9.3 CVE Dependencies Pull requests that update a dependency file Security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant