VendorsApacheopennlpall versions
Vulnerabilities

Apache Software Foundation OpenNLP

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-82617
Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns
Published 2026-09-11 · Analyzed
10.0EPSS 0.008
CVE-2017-12620
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.
Published 2017-10-02 · Modified
9.8EPSS 0.030
CVE-2026-42027
Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
Published 2026-05-04 · Modified
9.8EPSS 0.013
CVE-2026-40682
Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor
Published 2026-05-04 · Modified
9.1EPSS 0.008
CVE-2026-42440
Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
Published 2026-05-04 · Modified
7.5EPSS 0.011
CVE-2026-67211
Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerializer
Published 2026-09-11 · Analyzed
7.5EPSS 0.007
CVE-2026-43825
Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel
Published 2026-07-06 · Analyzed
7.3EPSS 0.139
CVE-2026-63317
Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML
Published 2026-07-24 · Analyzed
5.6EPSS 0.009