THREAT OPS › Threat News › [NVD] CVE-2026-40682 (CRITICAL 9.1) — XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor
Versions Affected: before 2.5.9, before 3.0.0-M3
Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling F
[NVD] CVE-2026-40682 (CRITICAL 9.1) — XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling F
CVE-2026-40682 CVSS: 9.1 CRITICAL Published: 2026-05-04T17:16:23.657
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor
Versions Affected: before 2.5.9, before 3.0.0-M3
Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCESSING or disabling DTD processi
Indicators of compromise
- CVE-2026-40682cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40682