Information on source package apache-opennlp

Available versions

ReleaseVersion
bookworm2.1.0-1
trixie2.5.3-1
forky2.5.12-1
sid2.5.12-1

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-82617vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedThe two built-in name-finder patterns exposed by opennlp.tools.namefin ...
CVE-2026-63317vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedArbitrary Class Instantiation via XML Feature Generator Descriptor and ...
CVE-2026-42440vulnerable (no DSA)vulnerable (no DSA)fixedfixedOOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP ...
CVE-2026-42027vulnerable (no DSA)vulnerable (no DSA)fixedfixedArbitrary Class Instantiation via Model Manifest in Apache OpenNLP Ext ...
CVE-2026-40682vulnerable (no DSA)vulnerable (no DSA)fixedfixedXML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache ...

Resolved issues

BugDescription
CVE-2026-67211OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP S ...
CVE-2026-43825Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versi ...
CVE-2017-12620When loading models or dictionaries that contain XML it is possible to ...

Search for package or bug name: Reporting problems