Apache disclosed CVE-2026-82617, a CVSS 4.0 10.0 critical denial-of-service flaw in OpenNLP's built-in EMAIL and URL regular-expression name finders exposed through RegexNameFinderFactory. Applications that process attacker-controlled text with the default finders can be affected without authentication or other special prerequisites.
Crafted email-like input lacking a terminating @ triggers super-linear, approximately quadratic regex backtracking that can consume CPU for seconds or minutes. URL query strings containing many ampersand-separated tokens can cause unbounded Java matcher recursion, raising an uncaught java.lang.StackOverflowError and terminating the calling thread. Apache OpenNLP opennlp-tools 2.0.0 through 2.5.11 and opennlp-core 3.0.0-M1 through 3.0.0-M5 are affected; organizations should upgrade to 2.5.12 or 3.0.0-M6.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-82617 was published for a denial-of-service flaw in Apache OpenNLP's built-in EMAIL and URL RegexNameFinderFactory patterns. Crafted input can cause quadratic regex backtracking or Java StackOverflowError; versions 2.0.0 through 2.5.11 and 3.0.0-M1 through 3.0.0-M5 are affected, with fixes in 2.5.12 and 3.0.0-M6.
A Nessus Unix-agent plugin identified CVE-2026-82617 as unpatched on Debian Linux 12.0, 13.0, and 14.0. The plugin reported no known public exploits and assessed the flaw as network-accessible with high availability impact.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcelists.apache.org
Open sourcecve.org
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.