CVE-2026-66756

EUVD-2026-51279
Improper Protection of Alternate Path vulnerability in Apache Tika.

This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.

Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 37.64%
Affected Products (NVD)
VendorProductVersion
apachetika
4.0.0:alpha1
apachetika
4.0.0:beta1-rc1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tika
sid
1.22-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tika
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
not-affected
xenial
not-affected