Your message dated Mon, 14 Sep 2026 08:35:11 +0000
with message-id <[email protected]>
and subject line Bug#1147511: fixed in apache-opennlp 2.5.12-1
has caused the Debian Bug report #1147511,
regarding apache-opennlp: CVE-2026-82617
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1147511: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147511
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: apache-opennlp
Version: 2.5.9-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for apache-opennlp.
CVE-2026-82617[0]:
| The two built-in name-finder patterns exposed by
| opennlp.tools.namefind.RegexNameFinderFactory -
| DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URLĀ -
| contain ambiguous nested quantifiers. An application that obtains
| these finders through
| RegexNameFinderFactory.getDefaultRegexNameFinders(...) and then
| applies them to untrusted text through
| RegexNameFinder.find(String[]) or RegexNameFinder.find(String) can
| be driven into super-linear backtracking or into unbounded matcher
| recursion by a small crafted input. For the EMAIL pattern, a
| long run of local-part characters that is never followed by an @
| forces the matcher to re-scan to end-of-input from every starting
| offset. Cost grows quadratically with input length: an input of
| approximately 32 KB consumes several seconds of CPU in a single
| find() call and returns no match, and each doubling of the input
| multiplies the cost roughly four-fold. For the URL pattern, the
| query-string sub-expression nests a capturing repetition inside an
| outer repetition. The JDK matcher recurses once per query token, so
| an input of approximately 4 KB containing many &-separated tokens
| exhausts the thread stack and causes java.lang.StackOverflowError to
| propagate out of find(), terminating the calling thread. On a thread
| created with a smaller stack (for example -Xss512k, typical of
| server worker pools) approximately 1 KB is sufficient. In both
| cases an attacker who can supply text for analysis can convert a
| single request into seconds to minutes of pinned CPU, or into an
| abrupt thread death, denying service to the embedding application.
| No authentication, special configuration, or model file is required
| beyond the application having selected one of the two built-in
| finders. This issue affects Apache OpenNLP: from 2.0.0 through
| 2.5.11; from 3.0.0-M1 through 3.0.0-M5. Users are
| recommended to upgrade to version 2.5.12, or to 3.0.0-M6 for users
| tracking the 3.0.0 milestone line, which fix the issue.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-82617
https://www.cve.org/CVERecord?id=CVE-2026-82617
[1] https://lists.apache.org/thread/spzhcxxszqdpppg70m1zz2l3mv29mhl3
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: apache-opennlp
Source-Version: 2.5.12-1
Done: Andrius Merkys <[email protected]>
We believe that the bug you reported is fixed in the latest version of
apache-opennlp, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Andrius Merkys <[email protected]> (supplier of updated apache-opennlp package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 14 Sep 2026 03:30:41 -0400
Source: apache-opennlp
Architecture: source
Version: 2.5.12-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Science Maintainers
<[email protected]>
Changed-By: Andrius Merkys <[email protected]>
Closes: 1142855 1147511
Changes:
apache-opennlp (2.5.12-1) unstable; urgency=medium
.
* New upstream version 2.5.12 (Closes: #1142855, #1147511)
[CVE-2026-63317, CVE-2026-82617]
Checksums-Sha1:
653fc8dd93a7c891d7904f49144a33499a49f48c 2082 apache-opennlp_2.5.12-1.dsc
cd206d06dfaa641921dbd7f2c1779f118530dd83 2850025
apache-opennlp_2.5.12.orig.tar.gz
975c84bb52302cf19faf27335c29c7fd193316f3 870
apache-opennlp_2.5.12.orig.tar.gz.asc
d3efe0ffdc0ecc10e4dfd482f9e495e5973cd8b7 36952
apache-opennlp_2.5.12-1.debian.tar.xz
4f75e3e3f07399e56ca5ac68d2398efdff239691 4988
apache-opennlp_2.5.12-1_source.buildinfo
Checksums-Sha256:
68a0d37e6d9c07fae6ebdfb325046581dfd0e2e115e9a05e2c53f7e1c66f0ef6 2082
apache-opennlp_2.5.12-1.dsc
5cdd8de1b1a5f13781ea494c3f48c56e8c9b67234f835a42848e9d66f644d525 2850025
apache-opennlp_2.5.12.orig.tar.gz
8524093615acb2fa3fa929a838335d225b8595067b835ee55b3d111d91848c1b 870
apache-opennlp_2.5.12.orig.tar.gz.asc
25c99e59a5397cafe15378e9cfba1da3458b2b8bb083f5f17557db564b23b505 36952
apache-opennlp_2.5.12-1.debian.tar.xz
57db8b276e083fb3513e9419730861db6282c04b0b310b179304bd14abaf8535 4988
apache-opennlp_2.5.12-1_source.buildinfo
Files:
6b0a911c44577602f7db62880ecefac0 2082 java optional apache-opennlp_2.5.12-1.dsc
3a4445672a41c2db4ff0d9b22fc6ccd6 2850025 java optional
apache-opennlp_2.5.12.orig.tar.gz
997bbc52ff5aa611621e8997b5927b04 870 java optional
apache-opennlp_2.5.12.orig.tar.gz.asc
fd7f495ee65ea59e57f99ea5af6bdcf3 36952 java optional
apache-opennlp_2.5.12-1.debian.tar.xz
26a47570c8a4dcf03856c88fda7237ce 4988 java optional
apache-opennlp_2.5.12-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQQ9mT++eHAQdiuDyvHYokBlilUePQUCaqemLgAKCRDYokBlilUe
PfJOAQCPJp4w14l3vhrctsItMne00jmAJKWowMpnv+SYHwOoZwD/SNchxtGeKflW
TzQc337lsKiPnNoa/sLTMF8jSY/DTAQ=
=GwFG
-----END PGP SIGNATURE-----
pgpZ25O74DzZq.pgp
Description: PGP signature
--- End Message ---