CVE-2026-40682CRITICAL 9.1EPSS p39.8%

CVE-2026-40682CVE-2026-40682

apache / opennlp

Description

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCESSING or disabling DTD processing. When create(InputStream, EntryInserter) is invoked, the only feature set on the XMLReader is namespace support — external entity resolution and DOCTYPE declarations remain fully enabled. An attacker who can supply a crafted dictionary file (e.g., a stop-word list or domain dictionary) containing a malicious DOCTYPE declaration can trigger local file disclosure via file:// entity references or server-side request forgery via http:// entity references during SAX parsing, before the application processes a single dictionary entry. This is inconsistent with the project's own XmlUtil.createSaxParser() helper, which correctly sets FEATURE_SECURE_PROCESSING and dis

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS0.50% probability of exploitation · percentile 39.8% · 2026-08-03T12:00:16Z
Published2026-05-04
Last modified2026-07-15

Underlying weaknesses· 1

CWE-611

References

  1. https://lists.apache.org/thread/r6jpt0qr9nj67gqhppqg7jxf8vsbo0w6
  2. http://www.openwall.com/lists/oss-security/2026/05/01/19

1

TypeTargetConfidenceTier
WeaknessImproper Restriction of XML External Entity Referencecwe-6110%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-42027
CVE
CVE-2025-54988
CVE
CVE-2025-66516
CVE
CVE-2025-10713
CVE
CVE-2024-55875
CVE
CVE-2025-2905
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.