Cyber Resilience

CVE-2018-1335

Apache Tika ≤ 1.18

Public PoCHigh EPSS
Published
25 April 2018
Modified
21 November 2024
CVSS Score v3 8.1
Click a component to see what it means
Raw vectorCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.94 99.8th percentile
Risk Priority 81 floored blend · peak EPSS

Summary

CVE-2018-1335 is a high-severity an unspecified weakness vulnerability in Apache Tika. Its CVSS base score is 8.1 (High).

Operationally, ranked in the top 0.2% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a…

more

server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1190 Exploit Public-Facing Application Initial Accessconfidence: HIGH
Crafted headers allow remote command injection into tika-server's command line, directly enabling exploitation of a public-facing application.
T1059 Command and Scripting Interpreter Executionconfidence: HIGH
Successful header injection results in arbitrary command execution on the host running tika-server.
inferred from description · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2025-66516Same product: Apache Tika
CVE-2025-54988Same product: Apache Tika
CVE-2025-23195Same vendor: Apache
CVE-2024-42362Same vendor: Apache
CVE-2021-30181Same vendor: Apache
CVE-2024-29070Same vendor: Apache
CVE-2023-28706Same vendor: Apache
CVE-2024-24773Same vendor: Apache
CVE-2026-56624Same vendor: Apache
CVE-2025-27696Same vendor: Apache

Affected Assets

apache
tika
≤ 1.18

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References