StanfordCVEs & Vulnerabilities

9 CVEs affecting Stanford products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

corenlp 5webauth 4stanford parser 1stanza 1
CVE-2026-54499HIGH

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(..., weights_only=True) but fall back to torch.load(..., weights_only=False) on attacker-controllable pickle.UnpicklingError, allowing a malicious .pt pretrain or model file to execute arbitrary pickle code when a Stanza NLP pipeline loads it. This issue is fixed in version 1.12.2.

9 Jul 2026
7.5
CVSS
CVE-2023-39020CRITICAL

stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.

28 Jul 2023
9.8
CVSS
CVE-2021-44550CRITICAL

An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).

24 Feb 2022
9.8
CVSS
CVE-2022-0239CRITICAL

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

17 Jan 2022
9.8
CVSS
CVE-2022-0198HIGH

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

13 Jan 2022
7.1
CVSS
CVE-2021-3869HIGH

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

19 Oct 2021
7.5
CVSS
CVE-2021-3878CRITICAL

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

15 Oct 2021
9.8
CVSS
CVE-2013-2106HIGH

webauth before 4.6.1 has authentication credential disclosure

3 Dec 2019
7.5
CVSS
CVE-2009-2945MEDIUM

weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

16 Sep 2009
4.3
CVSS
← PrevPage 1 / 1Next →