Skip to content

3x-ooxml-bigdecimal-dos - #2840

Merged
tballison merged 3 commits into
branch_3xfrom
3x-ooxml-bigdecimal-dos
May 27, 2026
Merged

3x-ooxml-bigdecimal-dos#2840
tballison merged 3 commits into
branch_3xfrom
3x-ooxml-bigdecimal-dos

Conversation

@tballison

@tballison tballison commented May 26, 2026

Copy link
Copy Markdown
Contributor

A potential bigdecimal dos was identified by @tonghuaroot. Many thanks for the report!

Along the way, claude found another potential DoS in the same area of the codebase.

This PR fixes both.

Thanks for your contribution to Apache Tika! Your help is appreciated!

Before opening the pull request, please verify that

  • there is an open issue on the Tika issue tracker which describes the problem or the improvement. We cannot accept pull requests without an issue because the change wouldn't be listed in the release notes.
  • the issue ID (TIKA-XXXX)
    • is referenced in the title of the pull request
    • and placed in front of your commit messages surrounded by square brackets ([TIKA-XXXX] Issue or pull request title)
  • commits are squashed into a single one (or few commits for larger changes)
  • Tika is successfully built and unit tests pass by running ./mvnw clean test
  • there should be no conflicts when merging the pull request branch into the recent main branch. If there are conflicts, please try to rebase the pull request branch on top of a freshly pulled main branch
  • if you add new module that downstream users will depend upon add it to relevant group in tika-bom/pom.xml.

We will be able to faster integrate your pull request if these conditions are met. If you have any questions how to fix your problem or about using Tika in general, please sign up for the Tika mailing list. Thanks!

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates OOXML custom property extraction to avoid the BigDecimal parsing DoS path by replacing POI/XMLBeans custom-property parsing with a bounded SAX-based parser, plus tests for decimal and text length caps.

Changes:

  • Adds length caps for custom property text and decimal parsing.
  • Parses docProps/custom.xml directly from the OPC package via SAX.
  • Adds unit tests covering capped buffering, oversized decimal rejection, and large string truncation.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.

File Description
MetadataExtractor.java Replaces XMLBeans custom property extraction with SAX-based extraction and capped decimal handling.
MetadataExtractorTest.java Adds tests for buffer capping and oversized custom-property values.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@tballison
tballison merged commit 394c737 into branch_3x May 27, 2026
1 check passed
@tballison
tballison deleted the 3x-ooxml-bigdecimal-dos branch September 4, 2026 00:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants