CVE-2026-82617
Apache OpenNLP’s built‑in email and URL regex patterns can be exploited with crafted text to trigger catastrophic backtracking or stack overflows. This causes the application to consume excessive CPU or crash a thread, effectively denying service. The issue is present in OpenNLP versions 2.0.0‑2.5.11 and 3.0.0‑M1‑M5.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache OpenNLP 2.0.0 through 2.5.11 and 3.0.0‑M1 through 3.0.0‑M5, used by developers who rely on the default regex name finders for email and URL detection.
Real-world impact
An attacker who can supply text to the name finder can make a single request take seconds or minutes of CPU time or cause a thread to crash, leading to denial of service for the application.
Why this severity
The CVSS score of 10 reflects the vulnerability’s ability to cause complete denial of service with no authentication or special configuration, combined with the high impact on availability and the lack of mitigations.
What to do about it
- 01Upgrade Apache OpenNLP to version 2.5.12 or later, or to 3.0.0-M6 or newer.
- 02Restart the application to load the updated library.
NVD-referenced vendor advisory
Timeline
- Sep 11, 2026 · 2d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 11, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.