Skip to content

[GHSA-4v8g-86x5-3vrc] Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing - #9440

Open
angelcrespoblanco-tng wants to merge 1 commit into
angelcrespoblanco-tng/advisory-improvement-9440from
angelcrespoblanco-tng-GHSA-4v8g-86x5-3vrc
Open

[GHSA-4v8g-86x5-3vrc] Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing#9440
angelcrespoblanco-tng wants to merge 1 commit into
angelcrespoblanco-tng/advisory-improvement-9440from
angelcrespoblanco-tng-GHSA-4v8g-86x5-3vrc

Conversation

@angelcrespoblanco-tng

Copy link
Copy Markdown

Updates

  • Affected products
  • Description

Comments
This advisory currently marks every org.apache.opennlp:opennlp-tools version below 2.5.9 as affected (introduced: "0"fixed: "2.5.9"), with 1.9.5 in the affected versions. This contradicts the CNA's (Apache Software Foundation, security@apache.org) own structured data for CVE-2026-40682: https://nvd.nist.gov/vuln/detail/cve-2026-40682

Per the CVE record (NVD affected field), the affected ranges are:

Range Status
[0, 1.9.5) affected
[2.0, 2.5.9) affected
[3.0.0-M1, 3.0.0-M3) affected
everything else unaffected (defaultStatus)

Consumers of the GitHub Advisory Database (Trivy, Dependabot, OSV mirrors, etc.) flag opennlp-tools 1.9.5 with a CRITICAL, "no fix below 2.5.9" finding. Example from Trivy:

org.apache.opennlp:opennlp-tools 1.9.5 — CRITICAL CVE-2026-40682 — fixed in: 2.5.9, 3.0.0-M3

This pushes users of the last (and fixed) 1.x release toward an unnecessary major-version upgrade (1.9.5 → 2.5.9).

@github-actions
github-actions Bot changed the base branch from main to angelcrespoblanco-tng/advisory-improvement-9440 September 10, 2026 12:31
@angelcrespoblanco-tng

Copy link
Copy Markdown
Author

There was another previous PR, but with a less comprehensive update: #8890

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant