PT-2026-82619 · Pypi · Nltk

·

CVE-2026-81724

·

Published

2026-08-27

·

Updated

2026-09-02

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NLTK versions prior to 3.10.3
Description An uncontrolled recursion issue exists in the nltk.featstruct.FeatStructReader class. Unauthenticated attackers can trigger a denial of service by providing deeply nested feature-structure input, such as payloads with nested brackets. This exceeds Python's recursion limit and triggers an unhandled RecursionError, which crashes applications that parse user-supplied feature structures or feature grammars.
Recommendations Update to version 3.10.3 or later.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81724
GHSA-CW6X-M8JW-QMRH
GHSA-PF76-Q698-37V8
PYSEC-2026-3739

Affected Products

Nltk