StackRadar

CVE-2026-40682

Critical

Advisory

Published 4 May 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 1
affected package

Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
opennlp-toolsmaven1.9.2, 1.9.4, 2.4.0, 2.5.4+1 more2.5.911
OSV records
GHSA-4v8g-86x5-3vrc

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2026-40682.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
opennlp-tools@1.9.2
2.5.9

Open the chart page →

6,048
thingsboardcetic0.1.21 of 2See more

thingsboard cetic 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-40682.

Container imageDigestPackageFixed in
thingsboard/tb-postgres:latest2d17e4e36edc
opennlp-tools@2.5.4
2.5.9

Open the chart page →

5,235
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-40682.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
opennlp-tools@1.9.2
2.5.9

Open the chart page →

24,930
tocktock0.6.33 of 9See more

tock tock 0.6.3

3 of the 9 container images this version deploys carry CVE-2026-40682.

Container imageDigestPackageFixed in
tock/bot_admin:25.10.7df3e38c77a38
opennlp-tools@2.5.5
2.5.9
tock/build_worker:25.10.7080cb6b08d5b
opennlp-tools@2.5.5
2.5.9
tock/nlp_api:25.10.7c04ffe67b977
opennlp-tools@2.5.5
2.5.9

Open the chart page →

12,907
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2026-40682.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
opennlp-tools@1.9.4
2.5.9

Open the chart page →

9,920
xwikikeyporttech0.2.01 of 2See more

xwiki keyporttech 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-40682.

Container imageDigestPackageFixed in
library/xwiki:lts-postgres-tomcat56490ac14a31
opennlp-tools@1.9.4
2.5.9

Open the chart page →

1,595
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-40682.

Container imageDigestPackageFixed in
vespaengine/vespa:8.526.1569b160f58211
opennlp-tools@2.4.0
2.5.9

Open the chart page →

6,338
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-40682.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
opennlp-tools@1.9.2
2.5.9

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2026-40682.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
opennlp-tools@1.9.2
2.5.9

Open the chart page →

8,806
languagetool-serverszpadel-chartsVerified publisher0.4.01 of 1See more

languagetool-server szpadel-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-40682.

Container imageDigestPackageFixed in
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
opennlp-tools@1.9.4
2.5.9

Open the chart page →

808
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-40682.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
opennlp-tools@1.9.4
2.5.9

Open the chart page →

1,571

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/solr:8.11.18c5f7881cebb
opennlp-tools@1.9.2
2.5.9
3
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
opennlp-tools@1.9.4
2.5.9
1
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
opennlp-tools@1.9.4
2.5.9
1
library/solr:8.7.0d124efd81fbb
opennlp-tools@1.9.2
2.5.9
1
library/xwiki:lts-postgres-tomcat56490ac14a31
opennlp-tools@1.9.4
2.5.9
1
thingsboard/tb-postgres:latest2d17e4e36edc
opennlp-tools@2.5.4
2.5.9
1
tock/bot_admin:25.10.7df3e38c77a38
opennlp-tools@2.5.5
2.5.9
1
tock/build_worker:25.10.7080cb6b08d5b
opennlp-tools@2.5.5
2.5.9
1
tock/nlp_api:25.10.7c04ffe67b977
opennlp-tools@2.5.5
2.5.9
1
vespaengine/vespa:8.526.1569b160f58211
opennlp-tools@2.4.0
2.5.9
1
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
opennlp-tools@1.9.4
2.5.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.