corenlp is vulnerable to Improper Restriction of XML External Entity Reference
{
"cna_assigner": "@huntrdev",
"cwe_ids": [
"CWE-611"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0239.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-0239.json"
"2026-04-11T23:37:34Z"
[
{
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/stanfordnlp/corenlp/commit/1940ffb938dc4f3f5bc5f2a2fd8b35aabbbae3dd",
"digest": {
"function_hash": "100764702940495631814522020455600243301",
"length": 831.0
},
"id": "CVE-2022-0239-8437e4b5",
"deprecated": false,
"target": {
"file": "src/edu/stanford/nlp/util/XMLUtils.java",
"function": "getValidatingXmlParser"
}
},
{
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/stanfordnlp/corenlp/commit/1940ffb938dc4f3f5bc5f2a2fd8b35aabbbae3dd",
"digest": {
"threshold": 0.9,
"line_hashes": [
"238565169868112149853538462787840540943",
"218625043191496645806240340423629875787",
"79570439888172606774987602873821909791",
"241063994109605614212165091553513739617"
]
},
"id": "CVE-2022-0239-a980c3ad",
"deprecated": false,
"target": {
"file": "src/edu/stanford/nlp/util/XMLUtils.java"
}
}
]