<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Tika-Server — PoC Archive</title><link>https://poc.intelseclab.com/tags/tika-server/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 31 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/tika-server/index.xml" rel="self" type="application/rss+xml"/><item><title>Apache Tika PDF Parser XXE via Crafted XFA Form (CVE-2025-54988)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-54988-apache-tika-xfa-xxe/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-54988-apache-tika-xfa-xxe/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-54988 (GHSA-p72g-pv48-7w9x, Apache JIRA TIKA-4459). Status: Weaponized. Affects: Apache Tika - tika-parser-pdf-module (and legacy tika-parsers). Tags: apache-tika, xxe, xfa, pdf-parsing, cwe-611, ssrf, file-disclosure, tika-server.</description><category>web</category><category>Critical</category><category>apache-tika</category><category>xxe</category><category>xfa</category><category>pdf-parsing</category><category>cwe-611</category><category>ssrf</category><category>file-disclosure</category><category>tika-server</category></item></channel></rss>