Your message dated Mon, 14 Sep 2026 08:35:11 +0000
with message-id <[email protected]>
and subject line Bug#1142855: fixed in apache-opennlp 2.5.12-1
has caused the Debian Bug report #1142855,
regarding apache-opennlp: CVE-2026-63317
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142855: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142855
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: apache-opennlp
Version: 2.5.9-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for apache-opennlp.
CVE-2026-63317[0]:
| Arbitrary Class Instantiation via XML Feature Generator Descriptor
| and Format Name in Apache OpenNLP Versions Affected: - before
| 2.5.10 - before 3.0.0-M5 Description: Three code paths in Apache
| OpenNLP load a class by its fully-qualified name via Class.forName()
| and invoke its no-arg constructor without any prior validation of
| the class name or its type. The affected paths are: (1)
| GeneratorFactory, which reads the class attribute of generator
| elements in an XML feature generator descriptor; such descriptors
| are embedded as artifacts in model archives (e.g. TokenNameFinder
| and POSTagger models) and are parsed during model loading, so an
| attacker who can supply a crafted model archive controls the class
| name directly. (2) StreamFactoryRegistry.getFactory(Class,
| String), which falls back to interpreting an unregistered format
| name as the fully-qualified class name of an ObjectStreamFactory;
| this is exploitable in applications that pass untrusted format names
| (e.g. exposing the -format parameter of the command-line tooling to
| external input). (3) StringInterners, which instantiates the
| interner implementation named by the opennlp.interner.class system
| property; this value is normally deployer-controlled, so it is
| hardened as defense in depth rather than being independently
| attacker-reachable. Exploitation requires a class with attacker-
| useful side effects in its static initializer or no-arg constructor
| (JNDI lookup, outbound network I/O, filesystem access) to be present
| on the classpath, so this is not drop-in remote code execution. T
| Mitigation: Upgrade to a fixed release. The fix routes all three
| paths through ExtensionLoader.instantiateExtension(...), which
| consults a package-prefix allowlist before Class.forName() is
| invoked, so a disallowed class is never loaded, initialized, or
| constructed. Classes under the opennlp. prefix remain permitted by
| default. Deployments that load models referencing feature generator
| factories, object stream factories, or string interners outside
| opennlp.* must opt those packages in, either programmatically via
| ExtensionLoader.registerAllowedPackage(String) before the first
| model load, or by setting the OPENNLP_EXT_ALLOWED_PACKAGES system
| property to a comma-separated list of allowed package prefixes.
| Users who cannot upgrade immediately should ensure all model files
| and format names are sourced from trusted origins and should audit
| their classpath for classes with side-effecting static initializers
| or constructors.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-63317
https://www.cve.org/CVERecord?id=CVE-2026-63317
[1] https://issues.apache.org/jira/browse/OPENNLP-1890
[2] https://lists.apache.org/thread/myr446n8t3gv8gq8wbpxm41olx16d8yj
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: apache-opennlp
Source-Version: 2.5.12-1
Done: Andrius Merkys <[email protected]>
We believe that the bug you reported is fixed in the latest version of
apache-opennlp, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Andrius Merkys <[email protected]> (supplier of updated apache-opennlp package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 14 Sep 2026 03:30:41 -0400
Source: apache-opennlp
Architecture: source
Version: 2.5.12-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Science Maintainers
<[email protected]>
Changed-By: Andrius Merkys <[email protected]>
Closes: 1142855 1147511
Changes:
apache-opennlp (2.5.12-1) unstable; urgency=medium
.
* New upstream version 2.5.12 (Closes: #1142855, #1147511)
[CVE-2026-63317, CVE-2026-82617]
Checksums-Sha1:
653fc8dd93a7c891d7904f49144a33499a49f48c 2082 apache-opennlp_2.5.12-1.dsc
cd206d06dfaa641921dbd7f2c1779f118530dd83 2850025
apache-opennlp_2.5.12.orig.tar.gz
975c84bb52302cf19faf27335c29c7fd193316f3 870
apache-opennlp_2.5.12.orig.tar.gz.asc
d3efe0ffdc0ecc10e4dfd482f9e495e5973cd8b7 36952
apache-opennlp_2.5.12-1.debian.tar.xz
4f75e3e3f07399e56ca5ac68d2398efdff239691 4988
apache-opennlp_2.5.12-1_source.buildinfo
Checksums-Sha256:
68a0d37e6d9c07fae6ebdfb325046581dfd0e2e115e9a05e2c53f7e1c66f0ef6 2082
apache-opennlp_2.5.12-1.dsc
5cdd8de1b1a5f13781ea494c3f48c56e8c9b67234f835a42848e9d66f644d525 2850025
apache-opennlp_2.5.12.orig.tar.gz
8524093615acb2fa3fa929a838335d225b8595067b835ee55b3d111d91848c1b 870
apache-opennlp_2.5.12.orig.tar.gz.asc
25c99e59a5397cafe15378e9cfba1da3458b2b8bb083f5f17557db564b23b505 36952
apache-opennlp_2.5.12-1.debian.tar.xz
57db8b276e083fb3513e9419730861db6282c04b0b310b179304bd14abaf8535 4988
apache-opennlp_2.5.12-1_source.buildinfo
Files:
6b0a911c44577602f7db62880ecefac0 2082 java optional apache-opennlp_2.5.12-1.dsc
3a4445672a41c2db4ff0d9b22fc6ccd6 2850025 java optional
apache-opennlp_2.5.12.orig.tar.gz
997bbc52ff5aa611621e8997b5927b04 870 java optional
apache-opennlp_2.5.12.orig.tar.gz.asc
fd7f495ee65ea59e57f99ea5af6bdcf3 36952 java optional
apache-opennlp_2.5.12-1.debian.tar.xz
26a47570c8a4dcf03856c88fda7237ce 4988 java optional
apache-opennlp_2.5.12-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQQ9mT++eHAQdiuDyvHYokBlilUePQUCaqemLgAKCRDYokBlilUe
PfJOAQCPJp4w14l3vhrctsItMne00jmAJKWowMpnv+SYHwOoZwD/SNchxtGeKflW
TzQc337lsKiPnNoa/sLTMF8jSY/DTAQ=
=GwFG
-----END PGP SIGNATURE-----
pgpbeUoYU8yeQ.pgp
Description: PGP signature
--- End Message ---