Vulnerabilities
Vulnerable Software
Stanford:  Security Vulnerabilities
Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(..., weights_only=True) but fall back to torch.load(..., weights_only=False) on attacker-controllable pickle.UnpicklingError, allowing a malicious .pt pretrain or model file to execute arbitrary pickle code when a Stanza NLP pipeline loads it. This issue is fixed in version 1.12.2.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-07-08
stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.
CVSS Score
9.8
EPSS Score
0.01
Published
2023-07-28
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).
CVSS Score
9.8
EPSS Score
0.013
Published
2022-02-24
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
CVSS Score
4.7
EPSS Score
0.012
Published
2022-01-17
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
CVSS Score
6.1
EPSS Score
0.007
Published
2022-01-13
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
CVSS Score
8.6
EPSS Score
0.014
Published
2021-10-19
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
CVSS Score
9.8
EPSS Score
0.019
Published
2021-10-15
webauth before 4.6.1 has authentication credential disclosure
CVSS Score
7.5
EPSS Score
0.016
Published
2019-12-03
weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
CVSS Score
4.3
EPSS Score
0.009
Published
2009-09-15


Contact Us

Shodan ® - All rights reserved