Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <2a9667f9-077a-1eef-4aac-3e0155d8cd18@apache.org>
Date: Thu, 30 Jul 2026 16:42:42 +0000
From: Tim Allison <tallison@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2026-66755: Apache Tika: Arbitrary Local File Read in
 ISArchiveParser 

Severity: 

Affected versions:

- Apache Tika (org.apache.tika:tika-parser-scientific-module) 1.8 before 3.3.2
- Apache Tika (org.apache.tika:tika-parser-scientific-module) 4.0.0-alpha-1 before 4.0.0-beta-1

Description:

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output, via a "Study Assay File Name" value in the ISA-Tab investigation file that traverses outside the dataset directory. Users are recommended to upgrade to version 3.3.2 or 4.0.0-beta-1, which fixes this issue.

Credit:

Reported by BugQore, who supplied a patch in PR #2873. (finder)
Independently reported with proposed fix by Rui Heng Koh. (finder)

References:

https://tika.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-66755

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.