PT-2026-82618 · Pypi · Nltk

·

CVE-2026-81723

·

Published

2026-08-27

·

Updated

2026-09-10

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NLTK versions prior to 3.10.3
Description A quadratic CPU exhaustion issue exists in the XMLCorpusView. read xml fragment() function. This occurs because the system rescans accumulated XML fragments for every 1 KiB block read. An attacker can exploit this by providing malformed XML corpus files, leading to severe CPU consumption and a denial of service through affected readers such as BNCCorpusReader.
Recommendations Update NLTK to version 3.10.3 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81723
ECHO-3EC1-214E-209E
GHSA-HQV3-XM29-P9HQ
GHSA-VP2X-QP44-57V7
PYSEC-2026-3871

Affected Products

Nltk