{"id":"CVE-2022-0239","summary":"Improper Restriction of XML External Entity Reference in stanfordnlp/corenlp","details":"corenlp is vulnerable to Improper Restriction of XML External Entity Reference","aliases":["GHSA-75vw-3m5v-fprh"],"modified":"2026-08-12T12:49:13.616899Z","published":"2022-01-17T06:15:11Z","database_specific":{"cna_assigner":"@huntrdev","cwe_ids":["CWE-611"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0239.json","unresolved_ranges":[{"extracted_events":[{"fixed":"4.3.3"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/a717aec2-5646-4a5f-ade0-dadc25736ae3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0239.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0239"},{"type":"FIX","url":"https://github.com/stanfordnlp/corenlp/commit/1940ffb938dc4f3f5bc5f2a2fd8b35aabbbae3dd"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/stanfordnlp/corenlp","events":[{"introduced":"0"},{"fixed":"04408ad02f1de8bbcc66040d6563387b9352f2f5"},{"fixed":"1940ffb938dc4f3f5bc5f2a2fd8b35aabbbae3dd"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"4.4.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:stanford:corenlp:*:*:*:*:*:*:*:*"}}],"versions":["v4.3.2","v4.2.2","v4.2.0","v4.1.0","v3.9.2b","v3.9.2","v3.9.1","v3.8.0","v3.7.0","v3.6.0","v3.5.2","v3.5.1","v3.5.0","v3.4.1","v3.4.0","v3.3.1","v3.3.0","v1.3.6","v1.3.5"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"100764702940495631814522020455600243301","length":831},"id":"CVE-2022-0239-8437e4b5","signature_type":"Function","signature_version":"v1","source":"https://github.com/stanfordnlp/corenlp/commit/1940ffb938dc4f3f5bc5f2a2fd8b35aabbbae3dd","target":{"file":"src/edu/stanford/nlp/util/XMLUtils.java","function":"getValidatingXmlParser"}},{"deprecated":false,"digest":{"line_hashes":["238565169868112149853538462787840540943","218625043191496645806240340423629875787","79570439888172606774987602873821909791","241063994109605614212165091553513739617"],"threshold":0.9},"id":"CVE-2022-0239-a980c3ad","signature_type":"Line","signature_version":"v1","source":"https://github.com/stanfordnlp/corenlp/commit/1940ffb938dc4f3f5bc5f2a2fd8b35aabbbae3dd","target":{"file":"src/edu/stanford/nlp/util/XMLUtils.java"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-0239.json","vanir_signatures_modified":"2026-08-12T12:49:13Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}