CVE-2026-82617
- EPSS 0.35%
- Veröffentlicht 11.09.2026 17:50:53
- Zuletzt bearbeitet 16.09.2026 14:05:52
The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifiers. An application that obtains these finders throu...
CVE-2026-67211
- EPSS 0.16%
- Veröffentlicht 11.09.2026 17:49:07
- Zuletzt bearbeitet 16.09.2026 14:04:32
OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. Releases 1.x and 2.x do not contain the affected c...
CVE-2026-63317
- EPSS 0.51%
- Veröffentlicht 24.07.2026 08:07:57
- Zuletzt bearbeitet 06.08.2026 00:48:32
Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three code paths in Apache OpenNLP load a class by its fully-qualified name v...
CVE-2026-43825
- EPSS 8.8%
- Veröffentlicht 06.07.2026 15:42:04
- Zuletzt bearbeitet 08.07.2026 19:46:24
Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm document categorization module; introduced in OPENNLP-1808 and only present on the 3.x line) Description: SvmDoccatModel.deserialize(Inpu...
CVE-2026-40682
- EPSS 0.5%
- Veröffentlicht 04.05.2026 16:55:55
- Zuletzt bearbeitet 02.09.2026 13:17:44
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at clas...
CVE-2026-42027
- EPSS 0.67%
- Veröffentlicht 04.05.2026 16:43:12
- Zuletzt bearbeitet 09.09.2026 13:19:55
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loads a class by...
CVE-2026-42440
- EPSS 0.6%
- Veröffentlicht 04.05.2026 16:40:32
- Zuletzt bearbeitet 30.07.2026 12:18:38
OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Versions Affected: before 1.9.5 before 2.5.9 before 3.0.0-M3 Description: The AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and get...
CVE-2017-12620
- EPSS 3.02%
- Veröffentlicht 03.10.2017 01:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6....