Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Ubuntu Security

USN-8717-1: Apache Tika vulnerability

  • What: Vulnerability in Apache Tika's ISA-Tab parser
  • Impact: Attackers can read arbitrary files via Tika
Read Full Article →

Ubuntu Security Notices USN-8717-1 USN-8717-1: Apache Tika vulnerability Publication date 3 September 2026 Overview Apache Tika could be made to expose sensitive information over the network. Releases 22.04 LTS 20.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages tika - A content analysis toolkit Details It was discovered that Apache Tika's ISA-Tab parser incorrectly handled file path resolution. An attacker who could place files in a directory that Tika subsequently parses could use this issue to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output. It was discovered that Apache Tika's ISA-Tab parser incorrectly handled file path resolution. An attacker who could place files in a directory that Tika subsequently parses could use this issue to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 22.04 LTS jammy libtika-java – 1.22-2+deb11u1ubuntu0.1~esm2 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 20.04 LTS focal libtika-java – 1.22-1ubuntu0.1~esm3 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-66755 CVE-2026-66755

Share this article