Impact
Apache OpenNLP’s SymSpellModelSerializer creates a LinkedHashMap sized directly from two counts that are only verified to be non‑negative and can be set to a very large value, triggering an attempt to allocate up to several gigabytes of backing array, causing an Out‑of‑MemoryError and a crash. This results in a denial‑of‑service condition to any process that loads such a file. The weakness is a classic unbounded memory allocation flaw, identified as CWE-789.
Affected Systems
The vulnerability exists in the opennlp-spellcheck extension shipped with Apache OpenNLP 3.0.0‑M4 and 3.0.0‑M5. Any code path that deserializes a SymSpell model—including SymSpellModels.deserialize, SymSpellModels.fromBytes, classpath model loading via SymSpellModelResolver, the CorrectTextTool command‑line tool, and model‑archive loading—can be exercised by an attacker.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in KEV. The exploitation scenario is straightforward: a crafted .bin file can be supplied via file upload, configuration, or any untrusted source that feeds a model into the extension. Because the exploit requires only a minimal payload of less than 100 bytes, the likelihood of successful deployment is high in environments that load models from arbitrary locations. The CVSS score is 7.5; nonetheless the impact and breadth of affected deployments indicate a severe threat.
OpenCVE Enrichment