- Package:
- src:apache-opennlp
- Source:
- src:apache-opennlp
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-14 08:37:04 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for apache-opennlp. CVE-2026-82617[0]: | The two built-in name-finder patterns exposed by | opennlp.tools.namefind.RegexNameFinderFactory - | DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - | contain ambiguous nested quantifiers. An application that obtains | these finders through | RegexNameFinderFactory.getDefaultRegexNameFinders(...) and then | applies them to untrusted text through | RegexNameFinder.find(String[]) or RegexNameFinder.find(String) can | be driven into super-linear backtracking or into unbounded matcher | recursion by a small crafted input. For the EMAIL pattern, a | long run of local-part characters that is never followed by an @ | forces the matcher to re-scan to end-of-input from every starting | offset. Cost grows quadratically with input length: an input of | approximately 32 KB consumes several seconds of CPU in a single | find() call and returns no match, and each doubling of the input | multiplies the cost roughly four-fold. For the URL pattern, the | query-string sub-expression nests a capturing repetition inside an | outer repetition. The JDK matcher recurses once per query token, so | an input of approximately 4 KB containing many &-separated tokens | exhausts the thread stack and causes java.lang.StackOverflowError to | propagate out of find(), terminating the calling thread. On a thread | created with a smaller stack (for example -Xss512k, typical of | server worker pools) approximately 1 KB is sufficient. In both | cases an attacker who can supply text for analysis can convert a | single request into seconds to minutes of pinned CPU, or into an | abrupt thread death, denying service to the embedding application. | No authentication, special configuration, or model file is required | beyond the application having selected one of the two built-in | finders. This issue affects Apache OpenNLP: from 2.0.0 through | 2.5.11; from 3.0.0-M1 through 3.0.0-M5. Users are | recommended to upgrade to version 2.5.12, or to 3.0.0-M6 for users | tracking the 3.0.0 milestone line, which fix the issue. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-82617 https://www.cve.org/CVERecord?id=CVE-2026-82617 [1] https://lists.apache.org/thread/spzhcxxszqdpppg70m1zz2l3mv29mhl3 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
apache-opennlp, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1147511@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Andrius Merkys <merkys@debian.org> (supplier of updated apache-opennlp package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 14 Sep 2026 03:30:41 -0400
Source: apache-opennlp
Architecture: source
Version: 2.5.12-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Science Maintainers <debian-science-maintainers@lists.alioth.debian.org>
Changed-By: Andrius Merkys <merkys@debian.org>
Closes: 1142855 1147511
Changes:
apache-opennlp (2.5.12-1) unstable; urgency=medium
.
* New upstream version 2.5.12 (Closes: #1142855, #1147511)
[CVE-2026-63317, CVE-2026-82617]
Checksums-Sha1:
653fc8dd93a7c891d7904f49144a33499a49f48c 2082 apache-opennlp_2.5.12-1.dsc
cd206d06dfaa641921dbd7f2c1779f118530dd83 2850025 apache-opennlp_2.5.12.orig.tar.gz
975c84bb52302cf19faf27335c29c7fd193316f3 870 apache-opennlp_2.5.12.orig.tar.gz.asc
d3efe0ffdc0ecc10e4dfd482f9e495e5973cd8b7 36952 apache-opennlp_2.5.12-1.debian.tar.xz
4f75e3e3f07399e56ca5ac68d2398efdff239691 4988 apache-opennlp_2.5.12-1_source.buildinfo
Checksums-Sha256:
68a0d37e6d9c07fae6ebdfb325046581dfd0e2e115e9a05e2c53f7e1c66f0ef6 2082 apache-opennlp_2.5.12-1.dsc
5cdd8de1b1a5f13781ea494c3f48c56e8c9b67234f835a42848e9d66f644d525 2850025 apache-opennlp_2.5.12.orig.tar.gz
8524093615acb2fa3fa929a838335d225b8595067b835ee55b3d111d91848c1b 870 apache-opennlp_2.5.12.orig.tar.gz.asc
25c99e59a5397cafe15378e9cfba1da3458b2b8bb083f5f17557db564b23b505 36952 apache-opennlp_2.5.12-1.debian.tar.xz
57db8b276e083fb3513e9419730861db6282c04b0b310b179304bd14abaf8535 4988 apache-opennlp_2.5.12-1_source.buildinfo
Files:
6b0a911c44577602f7db62880ecefac0 2082 java optional apache-opennlp_2.5.12-1.dsc
3a4445672a41c2db4ff0d9b22fc6ccd6 2850025 java optional apache-opennlp_2.5.12.orig.tar.gz
997bbc52ff5aa611621e8997b5927b04 870 java optional apache-opennlp_2.5.12.orig.tar.gz.asc
fd7f495ee65ea59e57f99ea5af6bdcf3 36952 java optional apache-opennlp_2.5.12-1.debian.tar.xz
26a47570c8a4dcf03856c88fda7237ce 4988 java optional apache-opennlp_2.5.12-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQQ9mT++eHAQdiuDyvHYokBlilUePQUCaqemLgAKCRDYokBlilUe
PfJOAQCPJp4w14l3vhrctsItMne00jmAJKWowMpnv+SYHwOoZwD/SNchxtGeKflW
TzQc337lsKiPnNoa/sLTMF8jSY/DTAQ=
=GwFG
-----END PGP SIGNATURE-----