CVE-2025-31672: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names

PJ Fanning <[email protected]> Tue, 08 Apr 2025 10:44:37 +0000
Newsgroups gmane.comp.jakarta.poi.user
Message-ID <[email protected]>
Severity: moderate

Affected versions:

- Apache POI before 5.4.0

Description:

Improper Input Validation vulnerability in Apache POI. The issue affects =
the parsing of OOXML format files like xlsx, docx and pptx. These file =
formats are basically zip files and it is possible for malicious users to =
add zip entries with duplicate names (including the path) in the zip. In =
this case, products reading the affected file could read different data =
because 1 of the zip entries with the duplicate name is selected over =
another but different products may choose a different zip entry.
This issue affects Apache POI poi-ooxml before 5.4.0. poi-ooxml 5.4.0 has a=
 check that throws an exception if zip entries with duplicate file names =
are found in the input file.
Users are recommended to upgrade to version poi-ooxml 5.4.0, which fixes =
the issue. Please read  https://poi.apache.org/security.html  for =
recommendations about how to use the POI libraries securely.

This issue is being tracked as bug-69620=20

References:

https://bz.apache.org/bugzilla/show_bug.cgi?id=3D69620
https://poi.apache.org/
https://www.cve.org/CVERecord?id=3DCVE-2025-31672
https://issues.apache.org/jira/browse/bug-69620