Tim Allison created TIKA-4938:
---------------------------------

             Summary: Migrate xfa parsing from stax to sax and cherry-pick back 
to 3.x
                 Key: TIKA-4938
                 URL: https://issues.apache.org/jira/browse/TIKA-4938
             Project: Tika
          Issue Type: Task
            Reporter: Tim Allison


CVE-2025-66516 was caused by finicky behavior in the JVM around return types 
for external entity handling in the stax parser. We found further differential 
behavior if woodstox is on the classpath (which it is in tika-server).

On this ticket, I propose simplifying our parsing of xfa and our parser 
configuration and moving xfa parsing to sax. We should deprecate the stax 
handling in XMLReaderUtils and try to keep any new xml parsing to SAX or DOM 
(only if necessary).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to