discovered 03 Aug 2026
CVE-2025-66516-Writeup-POC
→ View on GitHubThe CVE-2025-66516-Writeup-POC repository provides a detailed analysis and proof of concept for a critical XML External Entity (XXE) injection vulnerability in Apache Tika, with a CVSS score of 10.0. This vulnerability enables remote attackers to exploit specially crafted PDF documents to read arbitrary files and exfiltrate sensitive information. Notable features include specific details on affected versions, the technical breakdown of the vulnerability, and instructions for testing in a controlled environment.