13 Total advisories
13 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.apache.tika:tika-core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2025-66516
Apache Tika has XXE vulnerability
MEDIUM 5.5
CVE-2022-30126
Regular expression denial of service in apache tika
HIGH 8.1
CVE-2018-1335
Command injection in org.apache.tika:tika-core
CRITICAL 9.8
CVE-2016-6809
Apache Tika allows Java code execution for serialized objects embedded in MATLAB files
MEDIUM 5.5
CVE-2018-8017
Comparison errorr in org.apache.tika:tika-core
HIGH 8.8
CVE-2019-10088
Allocation of Resources Without Limits or Throttling in Apache Tika
MEDIUM 5.5
CVE-2022-30973
Regular expression denial of service in apache tika
HIGH 7.5
CVE-2018-11796
Apache Tika is vulnerable to entity expansions which can lead to a denial of service attack
HIGH 7.8
CVE-2019-10094
Allocation of Resources Without Limits or Throttling in Apache Tika
MEDIUM 5.5
CVE-2018-1338
Moderate severity vulnerability that affects org.apache.tika:tika-core
MEDIUM 5.9
CVE-2018-11762
Moderate severity vulnerability that affects org.apache.tika:tika-core
HIGH 7.5
CVE-2018-11761
High severity vulnerability that affects org.apache.tika:tika-core
HIGH 7.8
CVE-2016-4434
Apache Tika does not properly initialize the XML parser or choose handlers
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes