PT-2026-81156 · Pypi · Nltk

CVE-2026-78681

·

Published

2026-08-25

·

Updated

2026-09-08

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NLTK versions prior to 3.10.3
Description Multiple modules use the xml.etree.ElementTree library to parse XML, which honors entity declarations in document DTDs (Document Type Definitions). This allows attackers to craft XML payloads with nested entity declarations that expand significantly in memory, leading to a denial of service.
Recommendations Update NLTK to version 3.10.3 or later.

Exploit

Fix

DoS

XML Entity Expansion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78681
GHSA-97QJ-X29F-37W7
GHSA-JX89-3QG8-P2MR
PYSEC-2026-3748

Affected Products

Nltk