Tim Allison created TIKA-4938:
---------------------------------
Summary: Migrate xfa parsing from stax to sax and cherry-pick back
to 3.x
Key: TIKA-4938
URL: https://issues.apache.org/jira/browse/TIKA-4938
Project: Tika
Issue Type: Task
Reporter: Tim Allison
CVE-2025-66516 was caused by finicky behavior in the JVM around return types
for external entity handling in the stax parser. We found further differential
behavior if woodstox is on the classpath (which it is in tika-server).
On this ticket, I propose simplifying our parsing of xfa and our parser
configuration and moving xfa parsing to sax. We should deprecate the stax
handling in XMLReaderUtils and try to keep any new xml parsing to SAX or DOM
(only if necessary).
--
This message was sent by Atlassian Jira
(v8.20.10#820010)