Netskope Threat Labs

SERVER-WEBAPP Apache Tika XML external entity injection attempt

IPS-NPA

5 SIDs: 65658, 65659, 65660, 65661, 65662

Detects an attempt to exploit CVE-2025-54988, and CVE-2025-66516, an XML external entity flaw that can read server files or reach internal services in Apache Tika.