CVE-2022-25169

MEDIUM5.5EPSS 0.27%

Apache Tika vulnerable to uncontrolled memory consumption

Published: 5/17/2022Modified: 4/28/2026
Also known as:DEBIAN-CVE-2022-25169

Description

The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.5CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

References (7)