CVE-2022-30126

CVE-2022-30126: Apache Tika Regular Expression Denial of Service in Standards Extractor

Vendor Apache Software Foundation
Product Apache Tika
Published May 16, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

Description

In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0

Key dates

Disclosure timeline

May 16, 2022 CVE published
August 3, 2024 Record updated