VendorsApacheopennlpany version
Vulnerabilities

Apache Software Foundation OpenNLP any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-82617
Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns
Published 2026-09-11 · Analyzed
10.0EPSS 0.008
CVE-2026-42027
Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
Published 2026-05-04 · Modified
9.8EPSS 0.013
CVE-2026-40682
Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor
Published 2026-05-04 · Modified
9.1EPSS 0.008
CVE-2026-42440
Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
Published 2026-05-04 · Modified
7.5EPSS 0.011
CVE-2026-63317
Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML
Published 2026-07-24 · Analyzed
5.6EPSS 0.009