oss-sec mailing list archives
CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
From: Tim Allison <tallison () apache org>
Date: Thu, 30 Jul 2026 16:44:00 +0000
Severity: Affected versions: - Apache Tika (org.apache.tika:tika-server) 4.0.0-alpha-1 before 4.0.0-beta-1 Description: Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue. Credit: George Chen discovered this issue and proposed fixes (finder) References: https://tika.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-66756
Current thread:
- CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false Tim Allison (Jul 30)
