# CVE-2025-66516

**URL:** https://discuss.elastic.co/t/cve-2025-66516/384111
**Category:** Elastic Security
**Created:** [December 16, 2025, 1:18pm UTC](https://discuss.elastic.co/t/cve-2025-66516/384111 "2025-12-16T13:18:52Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![satyam\_mishra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/satyam_mishra/32/62921_2.png) [@satyam\_mishra](https://discuss.elastic.co/u/satyam_mishra)
#### Post date: [December 16, 2025, 1:18pm UTC](https://discuss.elastic.co/t/cve-2025-66516/384111/1 "2025-12-16T13:18:52Z")

</div>

_Is elasticsearch impacted by_ CVE-2025-66516 any version ?

---

<div class="post-metadata">

### Author: ![discourse\_ai\_spam](https://avatars.discourse-cdn.com/v4/letter/d/c68b51/32.png) [@discourse\_ai\_spam](https://discuss.elastic.co/u/discourse_ai_spam)
#### Post date: [December 16, 2025, 1:18pm UTC](https://discuss.elastic.co/t/cve-2025-66516/384111/2 "2025-12-16T13:18:54Z")

</div>



---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 16, 2025, 2:51pm UTC](https://discuss.elastic.co/t/cve-2025-66516/384111/3 "2025-12-16T14:51:59Z")

</div>



---

<div class="post-metadata">

### Author: ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)
#### Post date: [December 16, 2025, 11:23pm UTC](https://discuss.elastic.co/t/cve-2025-66516/384111/4 "2025-12-16T23:23:23Z")

</div>

The directory: _`elasticsearch/modules/ingest-attachment`_ contains around 11 tika libs.  
[According to GH](https://github.com/elastic/elasticsearch/pull/133410), the version \>8.18 and \>9.0 are upgraded with tika 3.2.2 in the ingest-attachment processor, should not be impacted.

However, you should wait for the official Elastic respond.

---

<div class="post-metadata">

### Author: ![Keith\_Massey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keith_massey/32/83666_2.png) [@Keith\_Massey](https://discuss.elastic.co/u/Keith_Massey)
#### Post date: [December 17, 2025, 4:09pm UTC](https://discuss.elastic.co/t/cve-2025-66516/384111/5 "2025-12-17T16:09:40Z")

</div>

All supported versions are safe from this bug because they have been upgraded to tika 3.2.2 ([Upgrading to tika 3.2.2 by masseyke · Pull Request #133410 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/pull/133410)). This includes 8.18.6+, 8.19.3+, 9.0.7+, 9.1.0, and anything higher than 9.1.0. We have also updated the low-level entitlements code in all supported versions to exclude java.xml from receiving the same broad privileges that the rest of the JVM has, in case some bug like this is re-introduced in tika in the future ([https://github.com/elastic/elasticsearch/pull/133671](https://github.com/elastic/elasticsearch/pull/133671)).

Older versions of Elasticsearch (pre 8.18) are actually immune to this because the Java security manager prevented the java.xml package from doing anything dangerous.
