CVE-2018-1335

HIGH EXPLOITED NUCLEI

Apache Tika <1.18 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-1335 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 8 public exploits from researchers including Metasploit, Rhino Security Labs, SkyBlueEternal, including a Metasploit module exploits/windows/http/apache_tika_jp2_jscript. A Nuclei detection template is also available.

AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in Apache Tika 1.15-1.17 on Windows by leveraging a malformed image/jp2 file and OCR parameters to execute arbitrary JScript code. It uses a PUT request with crafted headers to trigger the payload, achieving remote code execution.

Description

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

Exploits (8)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/47208

This Metasploit module exploits a command injection vulnerability in Apache Tika 1.15-1.17 on Windows by leveraging a malformed image/jp2 file and OCR parameters to execute arbitrary JScript code. It uses a PUT request with crafted headers to trigger the payload, achieving remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache Tika 1.15-1.17
No auth needed
Prerequisites: Network access to the target server · Apache Tika server running on Windows
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Rhino Security Labs · pythonremotewindows
https://www.exploit-db.com/exploits/46540

This PoC exploits CVE-2018-1335 in Apache Tika-server by sending a malicious HTTP PUT request with crafted headers and a JScript payload to achieve remote command execution. The exploit leverages the Tesseract OCR feature to execute arbitrary commands via WScript.Shell.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Apache Tika-server < 1.18
No auth needed
Prerequisites: Network access to the Tika-server instance · Tika-server with vulnerable version (< 1.18)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB 14 stars
by SkyBlueEternal · poc
https://github.com/SkyBlueEternal/CVE-2018-1335-EXP-GUI

The repository contains only a README file with minimal information about CVE-2018-1335, lacking any exploit code or technical details. No functional PoC or exploit logic is present.

Classification
Stub 10%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by canumay · remote
https://github.com/canumay/cve-2018-1335

This repository contains a detailed writeup and exploit code for CVE-2018-1335, a command injection vulnerability in Apache Tika-server versions 1.7 to 1.17. The exploit leverages unsanitized user input in HTTP headers to execute arbitrary commands on the target system.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache Tika-server < 1.18
No auth needed
Prerequisites: Vulnerable Apache Tika-server instance · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by DigitalNinja00 · remote
https://github.com/DigitalNinja00/CVE-2018-1335

This is a functional PoC for CVE-2018-1335, exploiting a remote code execution vulnerability in Apache Tika-server versions < 1.18 via malicious headers and JScript payloads. The exploit leverages the Tika server's OCR feature to execute arbitrary commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Apache Tika-server < 1.18
No auth needed
Prerequisites: Network access to vulnerable Tika-server instance · Python 2.x with requests library
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by siramk · remote
https://github.com/siramk/CVE-2018-1335

This exploit leverages CVE-2018-1335, a command injection vulnerability in Apache Tika, by manipulating headers to execute arbitrary commands via JScript. The PoC sends a crafted PUT request to the Tika server's /meta endpoint with malicious headers and payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Apache Tika (versions affected by CVE-2018-1335)
No auth needed
Prerequisites: Network access to the Tika server · Tika server with OCR enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by N0b1e6 · remote
https://github.com/N0b1e6/CVE-2018-1335-Python3

This exploit leverages CVE-2018-1335, a command injection vulnerability in Apache Tika, by sending a malicious HTTP PUT request with crafted headers and a JScript payload to execute arbitrary commands on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Apache Tika (versions before 1.18)
No auth needed
Prerequisites: Target must have Apache Tika exposed with the vulnerable endpoint accessible · Network access to the target host and port
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by h00die, David Yesland, Tim Allison · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/apache_tika_jp2_jscript.rb

This Metasploit module exploits a command injection vulnerability in Apache Tika 1.15-1.17 on Windows by leveraging a maliciously crafted JP2 file and JScript payload to achieve remote code execution via the OCR feature.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache Tika 1.15-1.17
No auth needed
Prerequisites: Network access to the target server · Apache Tika server running on Windows
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Apache Tika < 1.1.8 - Header Command Injection
HIGHby pikpikcu

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104001
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46540/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3140

Scores

CVSS v3 8.1
EPSS 0.9388
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-12-05
Status published
Products (2)
apache/tika < 1.18
org.apache.tika/tika-core 1.7 - 1.18Maven
Published Apr 25, 2018
Tracked Since Feb 18, 2026