PT-2026-82619 · Pypi · Nltk
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
NLTK versions prior to 3.10.3
Description
An uncontrolled recursion issue exists in the
nltk.featstruct.FeatStructReader class. Unauthenticated attackers can trigger a denial of service by providing deeply nested feature-structure input, such as payloads with nested brackets. This exceeds Python's recursion limit and triggers an unhandled RecursionError, which crashes applications that parse user-supplied feature structures or feature grammars.Recommendations
Update to version 3.10.3 or later.
Exploit
Fix
DoS
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nltk