Denial of Service Due to Unbounded Array Allocation in Apache OpenNLP
CVE-2026-42440

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
4 May 2026

What is CVE-2026-42440?

The vulnerability exists within the AbstractModelReader methods in Apache OpenNLP, where attacker-controlled values can lead to unbounded array allocations during model file deserialization. This allows an attacker to craft a .bin model file that, when loaded, can trigger an OutOfMemoryError, resulting in service disruption. This issue affects any code path that deserializes .bin models, making it critical for users to upgrade to the latest versions for mitigation.

Affected Version(s)

Apache OpenNLP 2.0 < 2.5.9

Apache OpenNLP 3.0.0-M1 < 3.0.0-M3

Apache OpenNLP 0 < 1.9.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Subramanian S
.