Apache Tika是美国阿帕奇(Apache)基金会的一个集成了POI(使用Java程序对MicrosoftOffice格式文档提供读和写功能的开源函数库)、Pdfbox(读取和创建PDF文档的纯Java类库)并为文本抽取工作提供了统一界面的内容抽取工具集合。 Apache Tika tika-core 1.13版本至3.2.1版本、tika-pdf-module 2.0.0版本至3.2.1版本和tika-parsers 1.13版本至1.28.5版本存在代码问题漏洞,该漏洞源于特制PDF文件中的XF
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Tika core | 1.13 ~ 3.2.1 | - |
|
| Apache Software Foundation | Apache Tika parsers | 1.13 ~ 2.0.0 | - |
|
| Apache Software Foundation | Apache Tika PDF parser module | 2.0.0 ~ 3.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/B1gh0rnn/CVE-2025-66516 | POC Details |
| 2 | CVE-2025-66516 | https://github.com/Ashwesker/Blackash-CVE-2025-66516 | POC Details |
| 3 | CVE-2025-66516 working exploit, scanner, explanation. | https://github.com/chasingimpact/CVE-2025-66516-Writeup-POC | POC Details |
| 4 | A POC for the CVE-2025-66516 Apache Tika Vulnerability for educational purposes only | https://github.com/sid6224/CVE-2025-66516-POC | POC Details |
| 5 | None | https://github.com/intSheep/Tika-CVE-2025-66516-Lab | POC Details |
| 6 | CVE-2025-66516 | https://github.com/Ashwesker/Ashwesker-CVE-2025-66516 | POC Details |
| 7 | Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1), and tika-parsers (1.13-1.28.5) contain an XML External Entity injection caused by processing crafted XFA files inside PDFs, letting attackers perform XXE attacks remotely, exploit requires crafted PDF input. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-66516.yaml | POC Details |
| 8 | CVE-2025-66516 | https://github.com/yunatamos/Blackash-CVE-2025-66516 | POC Details |
No public POC found.
Login to generate AI POCZaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.