Apache Software Foundation Apache OpenNLP是Apache Software Foundation基金会的自然语言处理库。 Apache OpenNLP 2.5.10之前版本和3.0.0-M5之前版本存在代码注入漏洞,该漏洞源于通过XML特征生成器描述符和格式名称加载类时未对类名和类型进行验证,可能导致任意类实例化,进而可能被利用实现远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache OpenNLP | 3.0.0-M1< 3.0.0-M4 |
affected |
< 2.5.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache OpenNLP | 3.0.0-M1 ~ 3.0.0-M4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49326 | Apache HBase: Missing scanner instance owner check in thrift delegation service | |
| CVE-2026-46452 | Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure | |
| CVE-2026-45816 | Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request | |
| CVE-2026-45815 | Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler | |
| CVE-2026-45813 | Apache NimBLE: Incorrect data validation in BASS add/modify source operation | |
| CVE-2026-45812 | Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler | |
| CVE-2026-45811 | Apache NimBLE: Buffer overflow in socket HCI transport | |
| CVE-2026-66144 | Apache Neethi: Remote PolicyReference fetch lacks resource bounds | |
| CVE-2026-66143 | Apache Neethi: Missing global alternative-output budget across policy computation paths | |
| CVE-2026-66142 | Apache Neethi: Uncontrolled recursion in policy processing |
No comments yet