Hi,
The following vulnerability was published for apache-opennlp.
CVE-2026-63317[0]:
| Arbitrary Class Instantiation via XML Feature Generator Descriptor
| and Format Name in Apache OpenNLP Versions Affected: - before
| 2.5.10 - before 3.0.0-M5 Description: Three code paths in Apache
| OpenNLP load a class by its fully-qualified name via Class.forName()
| and invoke its no-arg constructor without any prior validation of
| the class name or its type. The affected paths are: (1)
| GeneratorFactory, which reads the class attribute of generator
| elements in an XML feature generator descriptor; such descriptors
| are embedded as artifacts in model archives (e.g. TokenNameFinder
| and POSTagger models) and are parsed during model loading, so an
| attacker who can supply a crafted model archive controls the class
| name directly. (2) StreamFactoryRegistry.getFactory(Class,
| String), which falls back to interpreting an unregistered format
| name as the fully-qualified class name of an ObjectStreamFactory;
| this is exploitable in applications that pass untrusted format names
| (e.g. exposing the -format parameter of the command-line tooling to
| external input). (3) StringInterners, which instantiates the
| interner implementation named by the opennlp.interner.class system
| property; this value is normally deployer-controlled, so it is
| hardened as defense in depth rather than being independently
| attacker-reachable. Exploitation requires a class with attacker-
| useful side effects in its static initializer or no-arg constructor
| (JNDI lookup, outbound network I/O, filesystem access) to be present
| on the classpath, so this is not drop-in remote code execution. T
| Mitigation: Upgrade to a fixed release. The fix routes all three
| paths through ExtensionLoader.instantiateExtension(...), which
| consults a package-prefix allowlist before Class.forName() is
| invoked, so a disallowed class is never loaded, initialized, or
| constructed. Classes under the opennlp. prefix remain permitted by
| default. Deployments that load models referencing feature generator
| factories, object stream factories, or string interners outside
| opennlp.* must opt those packages in, either programmatically via
| ExtensionLoader.registerAllowedPackage(String) before the first
| model load, or by setting the OPENNLP_EXT_ALLOWED_PACKAGES system
| property to a comma-separated list of allowed package prefixes.
| Users who cannot upgrade immediately should ensure all model files
| and format names are sourced from trusted origins and should audit
| their classpath for classes with side-effecting static initializers
| or constructors.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-63317
https://www.cve.org/CVERecord?id=CVE-2026-63317
[1] https://issues.apache.org/jira/browse/OPENNLP-1890
[2] https://lists.apache.org/thread/myr446n8t3gv8gq8wbpxm41olx16d8yj
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore