Apache Opennlp vulnerabilities
5 known vulnerabilities affecting apache/opennlp.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH2
Vulnerabilities
Page 1 of 1
CVE-2026-42027P2CRITICALCVSS 9.8fixed in 2.5.9v3.0.0-m1+1 more2026-05-04
CVE-2026-42027 [CRITICAL] CWE-470 CVE-2026-42027: Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Aff
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader
Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3
Description:
The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via Class.forName() and invokes its no-arg constructor, with the class name sourced f
nvd
CVE-2026-40682P2CRITICALCVSS 9.1fixed in 2.5.9v3.0.0-m1+1 more2026-05-04
CVE-2026-40682 [CRITICAL] CWE-611 CVE-2026-40682: XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersis
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor
Versions Affected: before 2.5.9, before 3.0.0-M3
Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCESSING or disabling DTD processing. When create(Inp
nvd
CVE-2026-43825P2HIGHCVSS 7.3v3.0.0-m1v3.0.0-m2+1 more2026-07-06
CVE-2026-43825 [HIGH] CWE-502 CVE-2026-43825: Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M
Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel
Versions Affected:
before 3.0.0-M4 (libsvm document categorization module; introduced in
OPENNLP-1808 and only present on the 3.x line)
Description:
SvmDoccatModel.deserialize(InputStream) reads an attacker-controlled
stream with java.io.ObjectInputStream and calls readObject() without an
nvd
CVE-2017-12620P3CRITICALCVSS 9.8v1.5.0v1.5.1+8 more2017-10-03
CVE-2017-12620 [CRITICAL] CWE-611 CVE-2017-12620: When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.
nvd
CVE-2026-42440P3HIGHCVSS 7.5fixed in 2.5.9v3.0.0-m1+1 more2026-05-04
CVE-2026-42440 [HIGH] CWE-789 CVE-2026-42440: OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Version
OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader
Versions Affected:
before 1.9.5
before 2.5.9
before 3.0.0-M3
Description:
The AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and getPredicates() each read a 32-bit signed integer count field from a binary model stream and pass that value di
nvd