Apache OpenNLP是Apache基金会的一个自然语言处理工具库。 Apache OpenNLP 2.5.9之前版本和3.0.0-M3之前版本存在安全漏洞,该漏洞源于ExtensionLoader.instantiateExtension方法在类型检查前通过Class.forName加载并初始化类,可能导致攻击者利用特制模型存档执行类静态初始化器。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache OpenNLP | 2.0< 2.5.9 |
affected |
3.0.0-M1< 3.0.0-M3 |
affected | ||
< 1.9.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache OpenNLP | 2.0 ~ 2.5.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42810 | 9.9 CRITICAL | Apache Polaris: could broaden vended S3 credentials through wildcard-bearing namespace or |
| CVE-2026-42811 | 9.9 CRITICAL | Apache Polaris: could broaden vended GCS credentials through unescaped identifier content |
| CVE-2026-42809 | 9.9 CRITICAL | Apache Polaris: staged table creation could vend storage credentials for unvalidated locat |
| CVE-2026-42812 | 9.9 CRITICAL | Apache Polaris: No protection on `write.metadata.path` |
| CVE-2026-40682 | Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor | |
| CVE-2026-42440 | Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader | |
| CVE-2026-40563 | Apache Atlas: Script injection allows access to unintended data | |
| CVE-2026-29169 | Apache HTTP Server: mod_dav_lock indirect lock crash | |
| CVE-2026-23918 | Apache HTTP Server: http2: double free and possible RCE on early reset | |
| CVE-2026-33006 | Apache HTTP Server: mod_auth_digest timing attack | |
| CVE-2026-33007 | Apache HTTP Server: mod_authn_socache crash | |
| CVE-2026-33523 | Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status | |
| CVE-2026-33857 | Apache HTTP Server: Off-by-one OOB reads in AJP getter functions | |
| CVE-2026-34032 | Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination C | |
| CVE-2026-34059 | Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data | |
| CVE-2026-24072 | Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr |
No comments yet