Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN807
_____________________________________________________________________

DATE                : 03/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache Tika versions prior to
                               3.3.2, 4.0.0-beta-1.
 
=====================================================================
https://lists.apache.org/thread/f3qp581p9z4pgp5qqtbpbpbn0tzr4t29
https://lists.apache.org/thread/w1y0yd105bffjqpy9w051qlfn8sxs8b4
_____________________________________________________________________

CVE-2026-66755: Apache Tika: Arbitrary Local File Read in
ISArchiveParser

Severity:

Affected versions:

- Apache Tika (org.apache.tika:tika-parser-scientific-module) 1.8
before 3.3.2
- Apache Tika (org.apache.tika:tika-parser-scientific-module)
4.0.0-alpha-1 before 4.0.0-beta-1

Description:

Relative Path Traversal in the ISA-Tab parser in Apache Software
Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1,
allows an attacker who can place files in a directory that the
application subsequently parses to read arbitrary files accessible to
the Tika process and have their contents emitted into the extracted
text output, via a "Study Assay File Name" value in the ISA-Tab
investigation file that traverses outside the dataset directory.
Users are recommended to upgrade to version 3.3.2 or 4.0.0-beta-1,
which fixes this issue.

Credit:

Reported by BugQore, who supplied a patch in PR #2873. (finder)
Independently reported with proposed fix by Rui Heng Koh. (finder)

References:

https://tika.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-66755

_____________________________________________________________________

CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows
configuration with unsecureFeatures=false

Severity:

Affected versions:

- Apache Tika (org.apache.tika:tika-server) 4.0.0-alpha-1 before
4.0.0-beta-1

Description:

Improper Protection of Alternate Path vulnerability in Apache Tika.

This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.

Users are recommended to upgrade to version 4.0.0-beta-1, which fixes
the issue.

Credit:

George Chen discovered this issue and proposed fixes (finder)

References:

https://tika.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-66756


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




