corenlp is vulnerable to Improper Restriction of XML External Entity Reference
{
"cwe_ids": [
"CWE-611"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0239.json",
"cna_assigner": "@huntrdev",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"fixed": "4.3.3"
}
]
}
]
}{
"cpe": "cpe:2.3:a:stanford:corenlp:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.4.0"
}
]
}"2026-07-22T01:09:44Z"
[
{
"signature_type": "Function",
"target": {
"file": "src/edu/stanford/nlp/util/XMLUtils.java",
"function": "getValidatingXmlParser"
},
"deprecated": false,
"source": "https://github.com/stanfordnlp/corenlp/commit/1940ffb938dc4f3f5bc5f2a2fd8b35aabbbae3dd",
"id": "CVE-2022-0239-8437e4b5",
"signature_version": "v1",
"digest": {
"function_hash": "100764702940495631814522020455600243301",
"length": 831.0
}
},
{
"signature_type": "Line",
"target": {
"file": "src/edu/stanford/nlp/util/XMLUtils.java"
},
"deprecated": false,
"source": "https://github.com/stanfordnlp/corenlp/commit/1940ffb938dc4f3f5bc5f2a2fd8b35aabbbae3dd",
"id": "CVE-2022-0239-a980c3ad",
"signature_version": "v1",
"digest": {
"line_hashes": [
"238565169868112149853538462787840540943",
"218625043191496645806240340423629875787",
"79570439888172606774987602873821909791",
"241063994109605614212165091553513739617"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-0239.json"