Apache / Opennlp
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-82617 | Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns | CRITICAL | 10.0 | Sep 11, 2026 |
| CVE-2026-67211 | Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerializer | HIGH | 7.5 | Sep 11, 2026 |
| CVE-2026-63317 | Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML | MEDIUM | 5.8 | Jul 24, 2026 |
| CVE-2026-43825 | Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel | HIGH | 7.3 | Jul 6, 2026 |
| CVE-2026-40682 | Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor | CRITICAL | 9.1 | May 4, 2026 |
| CVE-2026-42027 | Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader | CRITICAL | 9.8 | May 4, 2026 |
| CVE-2026-42440 | Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader | HIGH | 7.5 | May 4, 2026 |
| CVE-2017-12620 | When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications… | CRITICAL | 9.8 | Oct 2, 2017 |
Showing 1 to 8 of 8 CVEs