As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-82617: Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns
CVE-2026-82617 affects Apache OpenNLP versions 3.0.0-M1 before 3.0.0-M6 and 2.0.0 before 2.5.12, where built-in regular expression patterns in RegexNameFinderFactory for EMAIL and URL matching contain ambiguous nested quantifiers. These patterns are susceptible to regular expression denial of service (ReDoS) and stack exhaustion attacks when processing specially crafted input.
Why it matters: Practitioners using OpenNLP for name-finding tasks must upgrade to patched versions (3.0.0-M6 or later, or 2.5.12 or later) to prevent attackers from causing denial of service through malformed email or URL strings.
- Source published
- First seen by Cybersecurity Tracker