THREATOPS
THREAT OPSThreat News › CVE-2026-82617: Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns

CVE-2026-82617: Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns

medoss_secPublished 2026-09-11

<p>Posted by Richard Zowalla on Sep 11</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache OpenNLP (org.apache.opennlp:opennlp-core) 3.0.0-M1 before 3.0.0-M6<br /> - Apache OpenNLP (org.apache.opennlp:opennlp-tools) 2.0.0 before 2.5.12<br /> <br /> Description:<br /> <br /> The two built-in name-finder patterns exposed by<br /> opennlp.tools.namefind.RegexNameFinderFactory - DEFAUL

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/722