What is CVE-2026-63317?
CVE-2026-63317 is an arbitrary class instantiation vulnerability in Apache OpenNLP via XML Feature Generator Descriptor and Format Name. It affects versions before 2.5.10 and 3.0.0-M5, allowing instantiation of attacker-supplied classes. Users must upgrade to the patched versions immediately.
Azərbaycanca: CVE-2026-63317, Apache OpenNLP-də XML Feature Generator Descriptor və Format Name vasitəsilə ixtiyari sinif yaratma zəifliyidir. 2.5.10 və 3.0.0-M5-dən əvvəlki versiyalar təsirlənir. İstifadəçilər dərhal yamalanmış versiyalara yüksəltməlidirlər.
FAQ2
Which product is affected by CVE-2026-63317?
This vulnerability affects Apache OpenNLP.
How can Apache OpenNLP users protect against CVE-2026-63317?
Users must upgrade to the patched versions 2.5.10 or 3.0.0-M5 immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.