Before reporting, review Tika's security model to understand what is and isn't considered a vulnerability.
Do NOT report security vulnerabilities through public GitHub or JIRA issues.
Report them privately to the Apache Security Team at security@apache.org, including:
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Any potential mitigations you have identified
Known vulnerabilities are published on the Apache Tika security page and in the CVE database.
| Version | Security updates |
|---|---|
| 4.x | Yes |
| 3.x | Yes |
| 2.x | No (EOL April 2025) |
| < 2.0 | No |