Description
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
No analysis available yet.
Remediation
Vendor Workaround
Users should upgrade to 1.26 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0949 | A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later. |
Github GHSA |
GHSA-567x-m4wm-87v8 | Infinite loop in Apache Tika |
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:27:59.935Z
Reserved: 2021-03-17T00:00:00.000Z
Link: CVE-2021-28657
No data.
Status : Modified
Published: 2021-03-31T08:15:11.267
Modified: 2024-11-21T06:00:02.613
Link: CVE-2021-28657
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA