Class.forName of the component GeneratorFactory/StreamFactoryRegistry/StringInterners. This manipulation of the argument opennlp.interner.class/-format causes use of externally-controlled input to select classes or code.
The identification of this vulnerability is CVE-2026-63317. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-63317 | Apache OpenNLP up to 2.5.10/3.0.0-M3 GeneratorFactory Class.forName opennlp.interner.class/-format externally-controlled input to select classes or code
Reagiere als Erste:r — dein Feedback zählt!
A vulnerability was found in Apache OpenNLP up to 2.5.10/3.0.0-M3. It has been rated as critical. This affects the function
SOCIAL SHARE CARD GENERATOR