Impact
The vulnerability is a regular‑expression denial of service (ReDoS) and stack exhaustion flaw in Apache OpenNLP’s built‑in EMAIL and URL name‑finder patterns. The regexes contain ambiguous nested quantifiers that allow an attacker to craft input that forces super‑linear backtracking or unbounded recursion. As a result, a call to RegexNameFinder.find can consume minutes of CPU time or trigger a java.lang.StackOverflowError, leading to significant denial of service for any application that processes untrusted text through these finders.
Affected Systems
The issue impacts Apache OpenNLP versions 2.0.0 through 2.5.11 and 3.0.0‑M1 through 3.0.0‑M5. The affected component is the RegexNameFinderFactory class in the Apache OpenNLP library distributed by the Apache Software Foundation.
Risk and Exploitability
The flaw is highly severe (CVSS 10) and can be triggered without authentication or special configuration—any untrusted input provided to RegexNameFinder.find is sufficient. Because the application can immediately invoke the vulnerable finders, an attacker can convert a single request into several seconds to minutes of CPU consumption or an abrupt thread death, effectively causing a denial of service. The EPSS score is low, at < 1%, and the vulnerability can be exploited immediately with untrusted input. Attackers could deliver malicious payloads through any user‑generated content that the application feeds to the OpenNLP library.
OpenCVE Enrichment