In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
{ "cpe": "cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*", "source": "CPE_FIELD", "extracted_events": [ { "introduced": "1.19" }, { "last_affected": "1.21" } ] }
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-10093.json"