CVE-2026-40682
Apache Software Foundation Apache OpenNLP, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Data Grid 8
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCESSING or disabling DTD processing. When create(InputStream, EntryInserter) is invoked, the only feature set on the XMLReader is namespace support — external entity resolution and DOCTYPE declarations remain fully enabled. An attacker who can supply a crafted dictionary file (e.g., a stop-word list or...
- CVSS
- 9.1
- EPSS
- 0.50% 39.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.05