Apache Software Foundation Apache Opennlp vulnerabilities
5 known vulnerabilities affecting apache_software_foundation/apache_opennlp.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-42027P2CRITICALCVSS 9.8≥ 2.0, < 2.5.9≥ 3.0.0-M1, < 3.0.0-M3+1 more2026-05-04
CVE-2026-42027 [CRITICAL] CWE-470 CVE-2026-42027: Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Aff
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader
Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3
Description:
The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via Class.forName() and invokes its no-arg constructor, with the class name sourced f
nvd
CVE-2026-40682P2CRITICALCVSS 9.1≥ 2.0, < 2.5.9≥ 3.0.0-M1, < 3.0.0-M3+1 more2026-05-04
CVE-2026-40682 [CRITICAL] CWE-611 CVE-2026-40682: XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersis
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor
Versions Affected: before 2.5.9, before 3.0.0-M3
Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCESSING or disabling DTD processing. When create(Inp
nvd
CVE-2017-12620P3CRITICALCVSS 9.8v1.5.0 to 1.5.3v1.6.0+2 more2017-10-03
CVE-2017-12620 [CRITICAL] CWE-611 CVE-2017-12620: When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.
nvd
CVE-2026-42440P3HIGHCVSS 7.5≥ 2.0, < 2.5.9≥ 3.0.0-M1, < 3.0.0-M3+1 more2026-05-04
CVE-2026-42440 [HIGH] CWE-789 CVE-2026-42440: OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Version
OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader
Versions Affected:
before 1.9.5
before 2.5.9
before 3.0.0-M3
Description:
The AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and getPredicates() each read a 32-bit signed integer count field from a binary model stream and pass that value di
nvd
CVE-2026-63317P3MEDIUMCVSS 5.6≥ 3.0.0-M1, < 3.0.0-M4fixed in 2.5.112026-07-24
CVE-2026-63317 [MEDIUM] CWE-470 CVE-2026-63317: Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP
Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP
Versions Affected:
- before 2.5.10
- before 3.0.0-M5
Description:
Three code paths in Apache OpenNLP load a class by its fully-qualified name via Class.forName() and invoke its no-arg constructor without any prior validation of the class name or
nvd