Apache disclosed CVE-2026-63317, a moderate-severity vulnerability in Apache OpenNLP that allows arbitrary class instantiation through multiple unvalidated extension-loading paths. The issue affects code paths that call Class.forName() and invoke a no-argument constructor without verifying the supplied class name or type, including model loading through XML feature generator descriptors in GeneratorFactory, untrusted format names handled by StreamFactoryRegistry, and the opennlp.interner.class system property.
Apache said exploitation depends on an attacker-useful class already being present on the application classpath and having side effects in its static initializer or constructor, making the flaw more constrained than typical remote code execution. The project fixed the issue by moving extension loading to an allowlist-based ExtensionLoader mechanism, and advised users to upgrade to patched releases and ensure model files, XML feature descriptors, and format names are accepted only from trusted sources.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Apache released fixed OpenNLP versions that replace the vulnerable extension-loading behavior with an allowlist-based ExtensionLoader mechanism. Users were advised to upgrade and to restrict model files and format names to trusted sources.
Apache disclosed CVE-2026-63317, a moderate-severity arbitrary class instantiation vulnerability in Apache OpenNLP caused by multiple Class.forName() code paths that instantiate attacker-influenced classes without validating class name or type. The disclosure described affected areas including XML feature generator descriptors, untrusted format names in StreamFactoryRegistry, and the opennlp.interner.class system property.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.