VDB
BDU%3A2026-00894
BDU%3A2026-00894
PUBLISHED
CVSS 10 CRITICAL
Уязвимость модулей tika-core, tika-pdf-module и tika-parsers среды обнаружения и анализа контента Apache Tika, позволяющая нарушителю проводить XXE-атаки
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Apache Software Foundation | Debian GNU/Linux, Tika Core, Tika Parsers, Tika PDF |
Timeline
- Jan 28, 2026 CVE Published
References
- https://lists.apache.org/thread/8xn3rqy6kz5b3l1t83kcofkw0w4mmj1w url
- https://lists.apache.org/thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k url
- https://www.openwall.com/lists/oss-security/2025/08/20/2 url
- https://www.openwall.com/lists/oss-security/2025/08/20/3 url
- https://lists.debian.org/debian-lts-announce/2025/10/msg00030.html url
- https://security-tracker.debian.org/tracker/CVE-2025-54988 url
- https://xakep.ru/2025/12/08/tika-xxe/ url