Loading HuntDB...

GHSA-mfwh-gqx8-c787

GitHub Security Advisory

Allocation of Resources Without Limits or Throttling in Apache Tika

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later.

Affected Packages

Maven org.apache.tika:tika-core
Affected versions: 1.7 (fixed in 1.22)

Related CVEs

Key Information

GHSA ID
GHSA-mfwh-gqx8-c787
Published
August 6, 2019 1:43 AM
Last Modified
May 5, 2021 10:58 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.tika:tika-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.