| Release | Version |
|---|---|
| bullseye | 1.9.3-1 |
| bookworm | 2.1.0-1 |
| trixie | 2.5.3-1 |
| forky | 2.5.9-1 |
| sid | 2.5.9-1 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2026-63317 | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable | vulnerable | Arbitrary Class Instantiation via XML Feature Generator Descriptor and ... |
| CVE-2026-42440 | vulnerable (no DSA) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP ... |
| CVE-2026-42027 | vulnerable (no DSA) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP Ext ... |
| CVE-2026-40682 | vulnerable (no DSA) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache ... |
| Bug | Description |
|---|---|
| CVE-2026-43825 | Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versi ... |
| CVE-2017-12620 | When loading models or dictionaries that contain XML it is possible to ... |