PT-2026-79565 · Pypi · Nltk

·

CVE-2026-66393

·

Published

2026-03-18

·

Updated

2026-08-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NLTK versions prior to 3.9.4
Description An unbounded recursion issue exists in the decode obj() function of the JSONTaggedDecoder. An attacker can cause a denial of service by providing deeply nested JSON structures. By crafting JSON payloads that exceed the recursion limit, an unhandled RecursionError is triggered, which crashes the Python process.
Recommendations Update NLTK to version 3.9.4 or later.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13471
CVE-2026-66393
GHSA-CV2G-M8RR-888C
GHSA-RF74-V2FM-23PW
PYSEC-2026-3724

Affected Products

Nltk