As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-67211: Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerializer
CVE-2026-67211 affects Apache OpenNLP versions 3.0.0-M4 and 3.0.0-M5, where the SymSpellModelSerializer.create() method is vulnerable to out-of-memory denial of service through unbounded map pre-sizing. The flaw was introduced in release 3.0.0-M4 and is patched in 3.0.0-M6.
Why it matters: Organizations using Apache OpenNLP 3.0.0-M4 or 3.0.0-M5 should upgrade to 3.0.0-M6 to prevent attackers from triggering out-of-memory conditions that could crash spell-check services.
- Source published
- First seen by Cybersecurity Tracker