Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY15 SECURITY RECORDS

Apache Software Foundation

Apache Tika

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-66756 30 Jul 2026 4.0.0-alpha-1 < 4.0.0-beta-1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-66755 30 Jul 2026 Apache Tika: 1.8 < 3.3.2, 4.0.0-alpha-1 < 4.0.0-beta-1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-33879 27 Jun 2022 Apache Tika < 2.4.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-30973 31 May 2022 Apache Tika ≤ 1.28.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-30126 16 May 2022 Apache Tika ≤ 1.28.1 Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Installation instructions are available from the Fuse 7.11.0 product documentation page: https://access.redhat.com/documentation/en-us/red_hat_fuse/7.11/ Update reference ↗
CVE-2022-25169 16 May 2022 Apache Tika ≤ 1.28.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-28657 31 Mar 2021 Apache Tika < 1.26 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2018-17197 24 Dec 2018 Apache Tika 1.8-1.19.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-11796 9 Oct 2018 Apache Tomcat 0.1 to 1.19 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-8017 19 Sep 2018 1.2 to 1.18 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-11762 19 Sep 2018 0.9 to 1.18 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-11761 19 Sep 2018 0.1 to 1.18 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2018-1339 25 Apr 2018 < 1.18 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-1338 25 Apr 2018 < 1.18 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-1335 25 Apr 2018 1.7 to 1.17 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.