XML External Entity (XXE) Injection Affecting elasticsearch-8 package, versions <8.19.2-r1


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
9.09% (95th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-ELASTICSEARCH8-12202805
  • published26 Aug 2025
  • disclosed20 Aug 2025

Introduced: 20 Aug 2025

CVE-2025-54988  (opens in a new tab)
CWE-611  (opens in a new tab)

How to fix?

Upgrade Chainguard elasticsearch-8 to version 8.19.2-r1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream elasticsearch-8 package and not the elasticsearch-8 package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard.

Users are recommended to upgrade to version 3.2.2, which fixes this issue.