Apache · Apache Tika · CVE-2025-54988
**Name of the Vulnerable Software and Affected Versions**
Apache Tika versions 1.13 through 3.2.1
**Description**
An XML External Entity (XXE) injection issue exists in the `tika-parser-pdf-module` due to improper restriction of XML references to external objects. An attacker can exploit this by providing a specially crafted XFA file embedded within a PDF, potentially allowing them to read sensitive data or trigger malicious requests to internal resources or third-party servers. This issue affects `tika-core`, `tika-pdf-module`, and `tika-parsers`, and is a dependency for several packages including `tika-parsers-standard-modules`, `tika-parsers-standard-package`, `tika-app`, `tika-grpc`, and `tika-server-standard`.
**Recommendations**
Upgrade Apache Tika to version 3.2.2.