Skip to content

[GHSA-4v8g-86x5-3vrc] Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing - #8890

Open
maheshwarivijaykumar wants to merge 1 commit into
maheshwarivijaykumar/advisory-improvement-8890from
maheshwarivijaykumar-GHSA-4v8g-86x5-3vrc
Open

[GHSA-4v8g-86x5-3vrc] Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing#8890
maheshwarivijaykumar wants to merge 1 commit into
maheshwarivijaykumar/advisory-improvement-8890from
maheshwarivijaykumar-GHSA-4v8g-86x5-3vrc

Conversation

@maheshwarivijaykumar

@maheshwarivijaykumar maheshwarivijaykumar commented Jul 30, 2026

Copy link
Copy Markdown

Updates

  • Affected products

Comments
The affected version range for org.apache.opennlp:opennlp-tools incorrectly collapses multiple disjoint CNA-published ranges into a single < 2.5.9 range, causing version 1.9.5 to be falsely reported as vulnerable.

The Apache Software Foundation (the CNA of record, security@apache.org) defines three separate affected ranges:

  • [0, 1.9.5)
  • [2.0, 2.5.9)
  • [3.0.0-M1, 3.0.0-M3)

with defaultStatus: unaffected. This represents a fixed → reintroduced → fixed lifecycle: the vulnerability was fixed in 1.9.5, reintroduced in the 2.x branch, and fixed again in 2.5.9. Consequently, 1.9.5 falls within the unaffected gap [1.9.5, 2.0) and should not be flagged as vulnerable.

Additionally, the advisory's own resolved-version enumeration is already consistent with this interpretation—it lists 1.9.0–1.9.4 as affected, but does not include 1.9.5. This indicates the version ranges are internally inconsistent with the versions list. Updating the ranges would align them with both the resolved-version enumeration and the CNA record.

Authoritative sources:

@github-actions
github-actions Bot changed the base branch from main to maheshwarivijaykumar/advisory-improvement-8890 July 30, 2026 13:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant