cbcvebase.

Apache Opennlp vulnerabilities

5 known vulnerabilities affecting apache/opennlp.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH2

Vulnerabilities

Page 1 of 1
CVE-2026-42027P2CRITICALCVSS 9.8fixed in 2.5.9v3.0.0-m1+1 more2026-05-04
CVE-2026-42027 [CRITICAL] CWE-470 CVE-2026-42027: Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Aff Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via Class.forName() and invokes its no-arg constructor, with the class name sourced f
nvd
CVE-2026-40682P2CRITICALCVSS 9.1fixed in 2.5.9v3.0.0-m1+1 more2026-05-04
CVE-2026-40682 [CRITICAL] CWE-611 CVE-2026-40682: XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersis XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCESSING or disabling DTD processing. When create(Inp
nvd
CVE-2026-43825P2HIGHCVSS 7.3v3.0.0-m1v3.0.0-m2+1 more2026-07-06
CVE-2026-43825 [HIGH] CWE-502 CVE-2026-43825: Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm document categorization module; introduced in OPENNLP-1808 and only present on the 3.x line) Description: SvmDoccatModel.deserialize(InputStream) reads an attacker-controlled stream with java.io.ObjectInputStream and calls readObject() without an
nvd
CVE-2017-12620P3CRITICALCVSS 9.8v1.5.0v1.5.1+8 more2017-10-03
CVE-2017-12620 [CRITICAL] CWE-611 CVE-2017-12620: When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.
nvd
CVE-2026-42440P3HIGHCVSS 7.5fixed in 2.5.9v3.0.0-m1+1 more2026-05-04
CVE-2026-42440 [HIGH] CWE-789 CVE-2026-42440: OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Version OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Versions Affected: before 1.9.5 before 2.5.9 before 3.0.0-M3 Description: The AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and getPredicates() each read a 32-bit signed integer count field from a binary model stream and pass that value di
nvd
Apache Opennlp vulnerabilities | cvebase