4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.apache.opennlp:opennlp-tools is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-42440
Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation
CRITICAL 9.1
CVE-2026-40682
Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing
CRITICAL 9.8
CVE-2026-42027
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
CRITICAL 9.8
CVE-2017-12620
Improper Restriction of XML External Entity Reference in Apache OpenNLP
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes