CVE-2022-0239Patch(stanford / corenlp)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch stanford corenlp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • corenlp

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
corenlp

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-15: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-15: 104-15
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • PulsePatch.io@pulsepatchio
    Patch

    `CoreNLP` is affected by an XML External Entity (XXE) vulnerability, CVE-2022-0239, potentially leading to data exposure. Configure XML parsers to disable external entities. #XXE #InfoSec #CyberSecurity https://www.pulsepatch.io/posts/cve-2022-0239-corenlp-xxe-vulnerability

    Post summary

    The post alerts to CoreNLP’s XXE vulnerability (CVE‑2022‑0239) and advises disabling XML external entities as a mitigation step.

    0000027
    12 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstanfordcorenlp---

Explore more