|
|
Message-ID: <2a9667f9-077a-1eef-4aac-3e0155d8cd18@apache.org> Date: Thu, 30 Jul 2026 16:42:42 +0000 From: Tim Allison <tallison@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2026-66755: Apache Tika: Arbitrary Local File Read in ISArchiveParser Severity: Affected versions: - Apache Tika (org.apache.tika:tika-parser-scientific-module) 1.8 before 3.3.2 - Apache Tika (org.apache.tika:tika-parser-scientific-module) 4.0.0-alpha-1 before 4.0.0-beta-1 Description: Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output, via a "Study Assay File Name" value in the ISA-Tab investigation file that traverses outside the dataset directory. Users are recommended to upgrade to version 3.3.2 or 4.0.0-beta-1, which fixes this issue. Credit: Reported by BugQore, who supplied a patch in PR #2873. (finder) Independently reported with proposed fix by Rui Heng Koh. (finder) References: https://tika.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-66755
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.