CVE-2025-54988: CWE-611 Improper Restriction of XML External Entity Reference in Apache Software Foundation Apache Tika PDF parser module
CVE-2025-54988 is a high-severity XML External Entity (XXE) vulnerability in the Apache Tika PDF parser module affecting versions 1.13 through 3.2.1. It allows attackers to inject malicious XML entities via crafted XFA files inside PDFs, potentially enabling unauthorized reading of sensitive data or triggering malicious requests to internal or external resources. The vulnerability impacts multiple Tika packages that depend on the vulnerable PDF parser module. Users are advised to upgrade to Apache Tika version 3.2.2, which addresses this issue.
AI Analysis
Technical Summary
This vulnerability (CVE-2025-54988) involves improper restriction of XML External Entity references (CWE-611) in the Apache Tika PDF parser module. Versions 1.13 through 3.2.1 on all platforms are affected. An attacker can exploit this by crafting a malicious XFA file embedded within a PDF document to perform XXE injection. This can lead to disclosure of sensitive information or cause the system to make unauthorized requests to internal or third-party servers. The vulnerable module is included as a dependency in several Apache Tika packages such as tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc, and tika-server-standard. The Apache Software Foundation has released version 3.2.2 to fix this vulnerability.
Potential Impact
Successful exploitation of this vulnerability can result in high impact including confidentiality, integrity, and availability consequences. Attackers may read sensitive data from the affected system or cause it to send malicious requests to internal or external resources, potentially leading to data leakage or further attacks. The CVSS v3.1 base score is 8.4, indicating a high severity level with attack vector local, low attack complexity, no privileges required, no user interaction, and impacts to confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in Apache Tika version 3.2.2. Users and administrators should upgrade affected Apache Tika installations to version 3.2.2 or later to remediate this vulnerability. Since this is not a cloud service, remediation depends on applying the official patch. No additional vendor advisory content is provided, so check the Apache Software Foundation's official security advisories for the latest updates and guidance.
CVE-2025-54988: CWE-611 Improper Restriction of XML External Entity Reference in Apache Software Foundation Apache Tika PDF parser module
Description
CVE-2025-54988 is a high-severity XML External Entity (XXE) vulnerability in the Apache Tika PDF parser module affecting versions 1.13 through 3.2.1. It allows attackers to inject malicious XML entities via crafted XFA files inside PDFs, potentially enabling unauthorized reading of sensitive data or triggering malicious requests to internal or external resources. The vulnerability impacts multiple Tika packages that depend on the vulnerable PDF parser module. Users are advised to upgrade to Apache Tika version 3.2.2, which addresses this issue.
CVSS v3.1
Score 8.4high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-54988) involves improper restriction of XML External Entity references (CWE-611) in the Apache Tika PDF parser module. Versions 1.13 through 3.2.1 on all platforms are affected. An attacker can exploit this by crafting a malicious XFA file embedded within a PDF document to perform XXE injection. This can lead to disclosure of sensitive information or cause the system to make unauthorized requests to internal or third-party servers. The vulnerable module is included as a dependency in several Apache Tika packages such as tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc, and tika-server-standard. The Apache Software Foundation has released version 3.2.2 to fix this vulnerability.
Potential Impact
Successful exploitation of this vulnerability can result in high impact including confidentiality, integrity, and availability consequences. Attackers may read sensitive data from the affected system or cause it to send malicious requests to internal or external resources, potentially leading to data leakage or further attacks. The CVSS v3.1 base score is 8.4, indicating a high severity level with attack vector local, low attack complexity, no privileges required, no user interaction, and impacts to confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in Apache Tika version 3.2.2. Users and administrators should upgrade affected Apache Tika installations to version 3.2.2 or later to remediate this vulnerability. Since this is not a cloud service, remediation depends on applying the official patch. No additional vendor advisory content is provided, so check the Apache Software Foundation's official security advisories for the latest updates and guidance.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- apache
- Date Reserved
- 2025-08-04T16:04:26.626Z
- State
- PUBLISHED
Threat ID: 68a62d6bad5a09ad0008befd
Added to database: 08/20/2025, 20:17:47 UTC
Last enriched: 05/28/2026, 21:24:52 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 373
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.