VYPR

rpm package

opensuse/opennlp&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/opennlp&distro=openSUSE%20Tumbleweed

Vulnerabilities (5)

  • CVE-2026-63317MedJul 24, 2026
    affected < 1.9.5-2.1fixed 1.9.5-2.1

    Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three code paths in Apache OpenNLP load a class by its fully-qualified name via Class.forName() and invoke

  • CVE-2026-42440HigMay 4, 2026
    affected < 1.9.5-1.1fixed 1.9.5-1.1

    OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3.0.0-M3  Description: The AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and getPredicates() each read a 32-bi

  • CVE-2026-42027CriMay 4, 2026
    affected < 1.9.5-1.1fixed 1.9.5-1.1

    Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description:  The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via

  • CVE-2026-40682CriMay 4, 2026
    affected < 1.9.5-1.1fixed 1.9.5-1.1

    XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling F

  • CVE-2017-12620CriOct 3, 2017
    affected < 1.9.5-1.1fixed 1.9.5-1.1

    When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.