CVE-2026-42027Disclosure(apache / opennlp)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch apache opennlp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description:  The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via Class.forName() and invokes its no-arg constructor, with the class name sourced from the manifest.properties entry of a model archive. The existing isAssignableFrom check correctly rejects classes that are not subtypes of the expected extension interface (BaseToolFactory for factory=, ArtifactSerializer for serializer-class-*), but the check runs after Class.forName() has already loaded and initialized the named class. Class.forName() with default initialization semantics executes the target class's static initializer before returning, so an attacker who can supply a crafted model archive can cause the static initializer of any class on the classpath to run during model loading, regardless of whether that class passes the subsequent type check. Exploitation requires a class with attacker-useful side effects in its static initializer (for example, JNDI lookup, outbound network I/O, or filesystem access) to be present on the classpath, so this is not a drop-in remote code execution; however, the attack surface grows as third-party model distribution becomes more common (community model repositories, Hugging Face-style sharing), where users routinely load model files from origins they do not control. A secondary, narrower vector affects deployments that ship legitimate BaseToolFactory or ArtifactSerializer subclasses with side-effecting no-arg constructors: a malicious manifest can name such a class and force its constructor to run during model load. Mitigation:  * 2.x users should upgrade to 2.5.9. * 3.x users should upgrade to 3.0.0-M3. Note: The fix introduces a package-prefix allowlist that is consulted before Class.forName() is invoked, so the static initializer of a disallowed class is never executed. Classes under the opennlp. prefix remain permitted by default. Deployments that load models referencing factories or serializers outside opennlp.* must opt those packages in, either programmatically via ExtensionLoader.registerAllowedPackage(String) before the first model load, or by setting the OPENNLP_EXT_ALLOWED_PACKAGES system property to a comma-separated list of allowed package prefixes. Users who cannot upgrade immediately should ensure that all model files are sourced from trusted origins and should audit their classpath for classes with side-effecting static initializers or constructors, particularly any that perform JNDI lookups, network requests, or filesystem operations during class initialization.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-470CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opennlp

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-13)
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
opennlp

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-05-02: 1Mentions · 2026-05-04: 1Mentions · 2026-05-13: 4Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-02: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-13: 305-0205-0405-13
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-021
Disclosure1
2026-05-041
Disclosure1
2026-05-134
Disclosure3Patch1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache OpenNLP CVE-2026-40682: XXE in DictionaryEntryPersistor https://www.openwall.com/lists/oss-security/2026/05/01/19 CVE-2026-42027: Arbitrary Class Instantiation in ExtensionLoader https://www.openwall.com/lists/oss-security/2026/05/01/20 CVE-2026-42440: OOM DoS in AbstractModelReader https://www.openwall.com/lists/oss-security/2026/05/01/21

    Post summary

    Apache OpenNLP announces three new CVEs—XXE (CVE-2026-40682), arbitrary class instantiation (CVE-2026-42027), and OOM DoS (CVE-2026-42440)—providing identifiers and references, but no evidence of exploitation, PoC, or patches.

    00022437
    4.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42027 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 2.5.9, before 3.0.0-M3…

    Post summary

    The text announces a critical CVE (CVE‑2026‑42027) affecting Apache OpenNLP due to arbitrary class instantiation via Model Manifest, providing CVSS and version details but no PoC, exploit, patch, or evidence of active exploitation.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Mitigation:  2.x users should upgrade to 2.5.9. 3.x users should upgrade to 3.0.0-M3. CVE: CVE-2026-42027 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The message announces a critical vulnerability (CVE-2026-42027) and advises users to upgrade to specific patched versions.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-42027 (CVSS 9.8) — multiple products. CVE: CVE-2026-42027 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    An advisory announces CVE-2026-42027 with a CVSS 9.8 critical rating and provides only severity and score details.

    1000034
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    https://lyrie.ai/research/research/cve-2026-42027-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text links to a CVE advisory but offers no additional details such as PoC, exploit code, active exploitation, or mitigation guidance, making it a generic disclosure reference.

    0000019
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42027 Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 2.5.9, before 3.0.0-M3 Description:  The Exten… https://www.cve.org/CVERecord?id=CVE-2026-42027

    Post summary

    Initial disclosure of CVE-2026-42027, affecting Apache OpenNLP versions before 2.5.9 and 3.0.0-M3, highlighting an arbitrary class instantiation vulnerability in the model manifest but providing no PoC, exploit code, or patch details.

    00000128
    57.4K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheopennlp---
Appapacheopennlp3.0.0--
Appapacheopennlp3.0.0--

Explore more