CVE-2018-8017: Apache Tika

Medium severity, CVSS 5.5. EPSS: 2.3% chance of exploitation in the next 30 days.

In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.

Affected products

  • Apache Tika: from 1.2, up to and including 1.18

Published 2018-09-19. Last modified 2026-06-17.