Skip to content

Security: apache/tika

Security

SECURITY.md

Security Policy

For known security vulnerabilities, see: https://tika.apache.org/security.html

Security Model

Before reporting, please review Tika's security model to understand what is and isn't considered a vulnerability:

Reporting a Vulnerability

The Apache Tika project takes security seriously. We appreciate your efforts to responsibly disclose your findings.

Please do NOT report security vulnerabilities through public GitHub or JIRA issues.

Instead, please report security vulnerabilities privately to the Apache Tika team and to the Apache Security Team:

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Affected versions
  • Any potential mitigations you've identified

Security Advisories

Known vulnerabilities are published at:

Supported Versions

We provide security updates for:

Version Supported
4.x
3.x
2.x ❌ (EOL April 2025)
< 2.0

There aren’t any published security advisories