In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0
Advisories
Source ID Title
EUVD EUVD EUVD-2022-5214 In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0
Github GHSA Github GHSA GHSA-rpjm-422r-95mh Regular expression denial of service in apache tika
Ubuntu USN Ubuntu USN USN-7529-1 Apache Tika vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

Upgrade to 1.28.2 or 2.4.0

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T06:40:47.590Z

Reserved: 2022-05-03T00:00:00

Link: CVE-2022-30126

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-16T17:15:09.640

Modified: 2024-11-21T07:02:12.520

Link: CVE-2022-30126

cve-icon Redhat

Severity : Low

Publid Date: 2022-05-16T00:00:00Z

Links: CVE-2022-30126 - Bugzilla

cve-icon OpenCVE Enrichment

No data.