CVE-2026-43825Disclosure(apache / opennlp)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache opennlp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introduced in   OPENNLP-1808 and only present on the 3.x line) Description: SvmDoccatModel.deserialize(InputStream) reads an attacker-controlled stream with java.io.ObjectInputStream and calls readObject() without an ObjectInputFilter installed. ObjectInputStream materialises every class referenced in the stream before the resulting object is cast to SvmDoccatModel, so the cast that follows readObject() executes only after the foreign object graph has already been deserialised in full. If a Java deserialization gadget chain is available on the consumer's classpath, a crafted payload supplied to deserialize() executes arbitrary code in the JVM that loads it. Apache OpenNLP itself does not ship a known gadget chain, so the realistic risk is to downstream applications that embed the libsvm module alongside vulnerable transitive dependencies. The method is public and static, so any caller can pass an untrusted stream to it directly. The practical impact is remote code execution against processes that load SvmDoccatModel instances from untrusted or semi-trusted origins. Mitigation: 3.x users should upgrade to 3.0.0-M4. Users who cannot upgrade immediately should treat all serialized SvmDoccatModel streams as untrusted input unless their provenance is verified, and should avoid invoking SvmDoccatModel.deserialize() on streams supplied by end users or fetched from third-party sources without integrity checks.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opennlp

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-07-06); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
opennlp

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-07-06: 2Mentions · 2026-07-08: 1Mentions · 2026-07-18: 1Mentions · 2026-07-19: 1Patch / Workaround · 2026-07-18: 1Patch / Workaround · 2026-07-19: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-18: 1Technical Details · 2026-07-19: 107-0607-0807-1807-19
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-062
Disclosure2
2026-07-081
Disclosure1
2026-07-181
Patch1
2026-07-191
General1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-43825: Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel https://www.openwall.com/lists/oss-security/2026/07/06/9 Severity: moderate remote code execution against processes that load SvmDoccatModel instances from untrusted or semi-trusted origins

    Post summary

    The post announces CVE‑2026‑43825, outlining a remote code execution flaw in Apache OpenNLP’s SvmDoccatModel due to unsafe Java deserialization, without evidence of exploitation, PoCs, or patches.

    00061657
    4.7K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-43825 3.0.0-M4以前のApache OpenNLP SvmDoccatModelの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/14/cve-2026-43825-300-m4apache-opennlp-svmdoccatmodel/ #IT #Security #cybersecurity

    Post summary

    The article offers an explanatory overview of CVE‑2026‑43825, covering its impact scope and mitigation steps, but does not present exploit code, evidence of active attacks, or any false‑positive claim.

    0000053
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-43825 3.0.0-M4以前のApache OpenNLP SvmDoccatModelの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/14/cve-2026-43825-300-m4apache-opennlp-svmdoccatmodel/ #IT #Security #cybersecurity

    Post summary

    The article explains CVE‑2026‑43825 in Apache OpenNLP SvmDoccatModel, detailing its impact and outlining mitigation steps.

    0000046
    208 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-43825 Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introduced in   OPENNLP-… https://www.cve.org/CVERecord?id=CVE-2026-43825 ----- Traducción: CVE-2026-43825 Des… http://infoflow.cloud`

    Post summary

    An Apache OpenNLP vulnerability (CVE-2026-43825) is disclosed as an untrusted Java deserialization issue affecting versions prior to 3.0.0-M4, with no PoC, exploit, patch, or active exploitation mentioned.

    0000037
    92 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43825 Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introduced in   OPENNLP-… https://www.cve.org/CVERecord?id=CVE-2026-43825

    Post summary

    The post announces CVE-2026-43825, highlighting untrusted Java deserialization in Apache OpenNLP's SvmDoccatModel and lists affected versions, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    00000853
    57.7K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheopennlp3.0.0--
Appapacheopennlp3.0.0--
Appapacheopennlp3.0.0--

Explore more