PT-2026-50238 · Pypi · Nltk

CVE-2026-12199

·

Published

2026-06-17

·

Updated

2026-06-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions nltk.app.wordnet app versions prior to 3.9.4
Description Insufficient authentication and protection mechanisms in the WordNet Browser HTTP server allow an unauthenticated remote user to shut down the local server when it is started in default mode. The server listens on all interfaces and processes a specific GET request to the endpoint "/SHUTDOWN%20THE%20SERVER", which triggers the os. exit(0) function to terminate the process immediately. This leads to a denial of service, impacting the availability of the service.
Recommendations Update to a version newer than 3.9.3.

Exploit

Fix

DoS

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12199

Affected Products

Nltk