Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm document categorization module
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
2주 이내 패치 — 우선 조치 대상
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L약점 (CWE)
- CWE-502
신뢰할 수 없는 데이터 역직렬화 — 조작된 객체 역직렬화로 코드 실행 위험.
상세 설명
Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel
Versions Affected:
before 3.0.0-M4 (libsvm document categorization module; introduced in
OPENNLP-1808 and only present on the 3.x line)
Description:
SvmDoccatModel.deserialize(InputStream) reads an attacker-controlled
stream with java.io.ObjectInputStream and calls readObject() without an
ObjectInputFilter installed. ObjectInputStream materialises every class
referenced in the stream before the resulting object is cast to
SvmDoccatModel, so the cast that follows readObject() executes only
after the foreign object graph has already been deserialised in full.
If a Java deserialization gadget chain is available on the consumer's
classpath, a crafted payload supplied to
deserialize() executes arbitrary code in the JVM that loads it. Apache
OpenNLP itself does not ship a known gadget chain, so the realistic
risk is to downstream applications that embed the libsvm module
alongside vulnerable transitive dependencies. The method is public and
static, so any caller can pass an untrusted stream to it directly.
The practical impact is remote code execution against processes that
load SvmDoccatModel instances from untrusted or semi-trusted origins.
Mitigation:
3.x users should upgrade to 3.0.0-M4.
Users who cannot upgrade immediately should treat all serialized
SvmDoccatModel streams as untrusted input unless their provenance is
verified, and should avoid invoking SvmDoccatModel.deserialize() on
streams supplied by end users or fetched from third-party sources
without integrity checks.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- apache opennlpother
- apache opennlpother
- apache opennlpother
영향받는 구성 (CPE) 3
- apache opennlp 3.0.0cpe:2.3:a:apache:opennlp:3.0.0:m1:*:*:*:*:*:*
- apache opennlp 3.0.0cpe:2.3:a:apache:opennlp:3.0.0:m2:*:*:*:*:*:*
- apache opennlp 3.0.0cpe:2.3:a:apache:opennlp:3.0.0:m3:*:*:*:*:*:*
참고 자료 2
- https://lists.apache.org/thread/c7kom0pgk9cbpfnbooh5m3g85ndf50hnMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/06/9Mailing ListThird Party Advisory
링크 내용 불러오는 중…