DIRAS TAKE
Act quickly: this flaw enables code execution when untrusted serialized data is processed and the vulnerable method can be invoked by any caller; prioritize updating to 3.0.0-M4 or preventing unverified serialized input from reaching the deserializer.
What is CVE-2026-43825?
An attacker can cause remote code execution in Apache OpenNLP :: Core :: ML :: LibSVM by supplying a crafted serialized stream to the SvmDoccatModel.deserialize method. CVE-2026-43825 affects the 3.x line: versions 3.0.0-M1 through before 3.0.0-M4; the vulnerability is fixed in 3.0.0-M4. Exploitation requires the ability to supply or make the application read an attacker-controlled Java serialization stream (no authentication or user interaction is required when an application calls the public static deserialize method on untrusted input). The weakness is classified as CWE-502 (Deserialization of Untrusted Data).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Which versions of Apache Software Foundation Apache OpenNLP :: Core :: ML :: LibSVM are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 3.x | 3.0.0-M1 – before 3.0.0-M4 | 3.0.0-M4 |
Is CVE-2026-43825 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-43825
- Upgrade Apache OpenNLP LibSVM on the 3.x line to 3.0.0-M4.
- Do not call SvmDoccatModel.deserialize() on streams from end users or third parties unless their origin is verified.
- Require integrity checks (digital signatures or strong checksums) for any serialized data before deserialization.
- Limit network exposure of services that accept serialized input and enable logging/alerting for unexpected deserialization activity.
Frequently asked questions
Is CVE-2026-43825 being actively exploited?
There are no public reports of exploitation of CVE-2026-43825 as of 2026-09-29.
Which Apache OpenNLP :: Core :: ML :: LibSVM versions are affected by CVE-2026-43825?
Versions on the 3.x branch from 3.0.0-M1 up to but not including 3.0.0-M4 are affected.
Is there a patch for CVE-2026-43825?
Yes: Apache OpenNLP LibSVM on the 3.x line is fixed in version 3.0.0-M4.
Does CVE-2026-43825 require authentication?
No; the issue is triggered by deserializing attacker-controlled data and the vulnerable method is public, so authentication is not required if the application invokes it on untrusted input.
References
- nvd.nist.gov/vuln/detail/CVE-2026-43825
- cve.org/CVERecord?id=CVE-2026-43825
- lists.apache.org/thread/c7kom0pgk9cbpfnbooh5m3g85ndf50hn
- All Apache Software Foundation CVEs on CVE Radar
- CVEs published in September 2026