Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch

Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch

Posted on December 5, 2025December 5, 2025 By CWS

Dec 05, 2025Ravie LakshmananApplication Safety / Vulnerability
A vital safety flaw has been disclosed in Apache Tika that would end in an XML exterior entity (XXE) injection assault.
The vulnerability, tracked as CVE-2025-66516, is rated 10.0 on the CVSS scoring scale, indicating most severity.
“Essential XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms permits an attacker to hold out XML Exterior Entity injection by way of a crafted XFA file inside a PDF,” in response to an advisory for the vulnerability.

It impacts the next Maven packages –

org.apache.tika:tika-core >= 1.13, <= 3.2.1 (Patched in model 3.2.2)
org.apache.tika:tika-parser-pdf-module >= 2.0.0, <= 3.2.1 (Patched in model 3.2.2)
org.apache.tika:tika-parsers >= 1.13, < 2.0.0 (Patched in model 2.0.0)

XXE injection refers to an online safety vulnerability that permits an attacker to intrude with an utility’s processing of XML knowledge. This, in flip, makes it doable to entry information on the applying server file system and, in some instances, even, obtain distant code execution.
CVE-2025-66516 is assessed to be the identical as CVE-2025-54988 (CVSS rating: 8.4), one other XXE flaw within the content material detection and evaluation framework that was patched by the venture maintainers in August 2025. The brand new CVE, the Apache Tika workforce stated, expands the scope of affected packages in two methods.
“First, whereas the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its repair have been in tika-core,” the workforce stated. “Customers who upgraded the tika-parser-pdf-module however didn’t improve tika-core to >= 3.2.2 would nonetheless be weak.”
“Second, the unique report failed to say that within the 1.x Tika releases, the PDFParser was within the “org.apache.tika:tika-parsers” module.”
In gentle of the criticality of the vulnerability, customers are suggested to use the updates as quickly as doable to mitigate potential threats.

The Hacker News Tags:Apache, Bug, Critical, CVE202566516, CVSS, Hits, Patch, Requires, Tika, Urgent, XXE

Post navigation

Previous Post: Threat Actors Deploying CoinMiner Malware via USB Drives Infecting Workstations
Next Post: Netflix Acquires Warner Bros. Studios and HBO in Landmark $82.7 Billion Megadeal

Related Posts

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading The Hacker News
Newly Patched Critical Microsoft WSUS Flaw Comes Under Active Exploitation Newly Patched Critical Microsoft WSUS Flaw Comes Under Active Exploitation The Hacker News
How to Integrate AI into Modern SOC Workflows How to Integrate AI into Modern SOC Workflows The Hacker News
Microsoft Shuts Down Malware-Signing Service Linked to Ransomware Microsoft Shuts Down Malware-Signing Service Linked to Ransomware The Hacker News
Malicious Chrome Extensions Target Google and Telegram Data Malicious Chrome Extensions Target Google and Telegram Data The Hacker News
Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical VMware vCenter Vulnerability Exploited by Hackers
  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow
  • Palo Alto Networks Addresses 11 Security Flaws in Latest Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical VMware vCenter Vulnerability Exploited by Hackers
  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow
  • Palo Alto Networks Addresses 11 Security Flaws in Latest Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark