• PATCH AVAILABLE

CVE-2026-43825: pre-auth remote code execution in Apache Software Foundation Apache OpenNLP :: Core :: ML :: LibSVM

An attacker can cause remote code execution in Apache OpenNLP :: Core :: ML :: LibSVM by supplying a crafted serialized stream to the SvmDoccatModel.deserialize method. CVE-2026-43825 affects the 3.x line: versions 3.0.0-M1 through before 3.0.0-M4; the vulnerability is fixed in 3.0.0-M4. Exploitation requires the ability to supply or make the application read an attacker-controlled Java serialization stream (no authentication or user interaction is required when an application calls the public static deserialize method on untrusted input).

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.3HIGH
EPSS
0.13921
CWE
CWE-502
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Act quickly: this flaw enables code execution when untrusted serialized data is processed and the vulnerable method can be invoked by any caller; prioritize updating to 3.0.0-M4 or preventing unverified serialized input from reaching the deserializer.

What is CVE-2026-43825?

An attacker can cause remote code execution in Apache OpenNLP :: Core :: ML :: LibSVM by supplying a crafted serialized stream to the SvmDoccatModel.deserialize method. CVE-2026-43825 affects the 3.x line: versions 3.0.0-M1 through before 3.0.0-M4; the vulnerability is fixed in 3.0.0-M4. Exploitation requires the ability to supply or make the application read an attacker-controlled Java serialization stream (no authentication or user interaction is required when an application calls the public static deserialize method on untrusted input). The weakness is classified as CWE-502 (Deserialization of Untrusted Data).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Which versions of Apache Software Foundation Apache OpenNLP :: Core :: ML :: LibSVM are affected?

BRANCHAFFECTEDFIXED
3.x3.0.0-M1 – before 3.0.0-M43.0.0-M4

Is CVE-2026-43825 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-43825

  1. Upgrade Apache OpenNLP LibSVM on the 3.x line to 3.0.0-M4.
  2. Do not call SvmDoccatModel.deserialize() on streams from end users or third parties unless their origin is verified.
  3. Require integrity checks (digital signatures or strong checksums) for any serialized data before deserialization.
  4. Limit network exposure of services that accept serialized input and enable logging/alerting for unexpected deserialization activity.

Frequently asked questions

Is CVE-2026-43825 being actively exploited?

There are no public reports of exploitation of CVE-2026-43825 as of 2026-09-29.

Which Apache OpenNLP :: Core :: ML :: LibSVM versions are affected by CVE-2026-43825?

Versions on the 3.x branch from 3.0.0-M1 up to but not including 3.0.0-M4 are affected.

Is there a patch for CVE-2026-43825?

Yes: Apache OpenNLP LibSVM on the 3.x line is fixed in version 3.0.0-M4.

Does CVE-2026-43825 require authentication?

No; the issue is triggered by deserializing attacker-controlled data and the vulnerable method is public, so authentication is not required if the application invokes it on untrusted input.

References