CVE Explorer
CVE-2026-43825
Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel
Versions Affected:
before 3.0.0-M4 (libsvm document categorization module; introduced in
OPENNLP-1808 and only present on the 3.x line)
Description:
SvmDoccatModel.deserialize(InputStream) reads an attacker-controlled
stream with java.io.ObjectInputStream and calls readObject() without an
ObjectInputFilter installed. ObjectInputStream materialises every class
referenced in the stream before the resulting object is cast to
SvmD
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://repo.maven.apache.org/maven2","defaultStatus":"unaffected","packageName":"org.apache.opennlp:opennlp-ml-libsvm","product":"Apache OpenNLP :: Core :: ML :: LibSVM","vendor":"Apache Software Foundation","versions":[{"lessThan":"3.0.0-M4","status":"affected","version":"3.0.0-M1","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c6850f406afd178152f5af21b0ea968a12150a43b57042f2d2269cea0039d92a · sha256:b7de6e01f49cb5e0… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c6850f406afd178152f5af21b0ea968a12150a43b57042f2d2269cea0039d92a · sha256:b7de6e01f49cb5e0… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-502","description":"CWE-502 Deserialization of Untrusted Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c6850f406afd178152f5af21b0ea968a12150a43b57042f2d2269cea0039d92a · sha256:b7de6e01f49cb5e0… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/07/06/9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c6850f406afd178152f5af21b0ea968a12150a43b57042f2d2269cea0039d92a · sha256:b7de6e01f49cb5e0… · /containers/adp/1/references/0
{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/c7kom0pgk9cbpfnbooh5m3g85ndf50hn"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c6850f406afd178152f5af21b0ea968a12150a43b57042f2d2269cea0039d92a · sha256:b7de6e01f49cb5e0… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.