CVE-2019-10093: Apache Tika

Medium severity, CVSS 6.5. EPSS: 3.7% chance of exploitation in the next 30 days.

In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.

Affected products

  • Apache Tika: from 1.19, up to and including 1.21

Published 2019-08-02. Last modified 2026-06-17.