Arbitrary Class Instantiation Vulnerability in Apache OpenNLP by Apache
CVE-2026-63317

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
24 July 2026

What is CVE-2026-63317?

Apache OpenNLP contains a vulnerability that allows for arbitrary class instantiation via XML feature generator descriptors and format names. This issue arises from three code paths that load a class by its fully-qualified name without proper validation, which can be exploited if an attacker supplies a maliciously crafted model archive. The affected functionalities include reading generator elements from model archives and interpreting untrusted format names as class names. The potential for exploitation increases when harmful classes with side effects are present in the classpath. To mitigate this risk, users are advised to upgrade to the latest fixed release or ensure that all model files and format names are trusted.

Affected Version(s)

Apache OpenNLP 3.0.0-M1 < 3.0.0-M4

Apache OpenNLP 0 < 2.5.11

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Subramanian S
.