Apache

Opennlp

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 11.09.2026 17:50:53
  • Zuletzt bearbeitet 16.09.2026 14:05:52

The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifiers. An application that obtains these finders throu...

  • EPSS 0.16%
  • Veröffentlicht 11.09.2026 17:49:07
  • Zuletzt bearbeitet 16.09.2026 14:04:32

OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. Releases 1.x and 2.x do not contain the affected c...

  • EPSS 0.51%
  • Veröffentlicht 24.07.2026 08:07:57
  • Zuletzt bearbeitet 06.08.2026 00:48:32

Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three code paths in Apache OpenNLP load a class by its fully-qualified name v...

  • EPSS 8.8%
  • Veröffentlicht 06.07.2026 15:42:04
  • Zuletzt bearbeitet 08.07.2026 19:46:24

Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introduced in   OPENNLP-1808 and only present on the 3.x line) Description: SvmDoccatModel.deserialize(Inpu...

  • EPSS 0.5%
  • Veröffentlicht 04.05.2026 16:55:55
  • Zuletzt bearbeitet 02.09.2026 13:17:44

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at clas...

  • EPSS 0.67%
  • Veröffentlicht 04.05.2026 16:43:12
  • Zuletzt bearbeitet 09.09.2026 13:19:55

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description:  The ExtensionLoader.instantiateExtension(Class, String) method loads a class by...

  • EPSS 0.6%
  • Veröffentlicht 04.05.2026 16:40:32
  • Zuletzt bearbeitet 30.07.2026 12:18:38

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3.0.0-M3  Description: The AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and get...

Exploit
  • EPSS 3.02%
  • Veröffentlicht 03.10.2017 01:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6....