On Fri, May 27, 2016 at 11:58:33AM +0200, Moritz Muehlenhoff wrote: > please see http://seclists.org/oss-sec/2016/q2/413 for details. That link says: Versions Affected: Apache Tika 0.10 to 1.12 So perhaps 1.5 isn't affected after all? I tried to find the relevant commit in the upstream git but failed :( Regards, Faidon