CVE Vulnerabilities

CVE-2025-66516

Improper Restriction of XML External Entity Reference

Published: Dec 04, 2025 | Modified: Dec 18, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
10 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF.

This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways.

First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable.

Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the org.apache.tika:tika-parsers module.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Tika Apache 1.13 (including) 3.2.2 (excluding)
Red Hat build of Apache Camel 4.14.2 for Spring Boot 3.5.8 RedHat tika-core *
Red Hat OpenShift Dev Spaces (RHOSDS) 3.25 RedHat devspaces/openvsx-rhel9:sha256:5b136fff0f0c8ff4d56fdb934eef1dd7d04ebdac13e7cb8c1e020bf370f4df84 *
Red Hat OpenShift Dev Spaces (RHOSDS) 3.25 RedHat devspaces/pluginregistry-rhel9:sha256:f67c1d7d8549587c1032404411b01472f71e775a7bbfd91927060c1b09a631c0 *

Potential Mitigations

References