{"id":"CVE-2026-33231","title":"NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing","summary":"NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthentic…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-306"],"vendor":"nltk","product":"nltk","affected":["nltk <= 3.9.3"],"patched":["openshift_ai 2.25","openshift_ai 3.3"],"published":"2026-03-20","updated":"2026-09-09","sourceUpdated":"2026-09-09T13:19:24.380","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33231","references":[{"url":"https://github.com/nltk/nltk/commit/bbaae83db86a0f49e00f5b0db44a7254c268de9b","label":"security-advisories@github.com"},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-jm6w-m3j8-898g","label":"security-advisories@github.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:19712","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24977","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:37275","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:65126","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-33231","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2449836","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33231.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-33231"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33231"},{"url":"https://github.com/nltk/nltk"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat","osv","pip"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-03-25T13:43:39.454391Z"},"epss":0.01215,"epssPercentile":0.66752,"ingestedAt":"2026-07-10T13:03:45.497Z","aliases":["GHSA-jm6w-m3j8-898g","PYSEC-2026-2236"],"ecosystem":"pip","slug":"CVE-2026-33231","body":"## Overview\n\nNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when it is started in its default mode. A simple `GET /SHUTDOWN%20THE%20SERVER` request causes the process to terminate immediately via `os._exit(0)`, resulting in a denial of service. Commit bbaae83db86a0f49e00f5b0db44a7254c268de9b patches the issue.\n\n## Affected\n\n- `nltk <= 3.9.3`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:24977** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-06-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:24977)\n- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)\n- **RHSA-2026:19712** · Red Hat · fixed in: Red Hat OpenShift AI 3.3 · released 2026-05-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:19712)\n- **RHSA-2026:37275** · Red Hat · fixed in: Red Hat OpenShift AI 3.3 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37275)\n- **Red Hat VEX** · Important · affected: Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI) · no fix planned: OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Lightspeed Core, Red Hat OpenShift AI (RHOAI) · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33231.json)\n\n## Package advisory (CVE-2026-33231)\n\nAffected packages:\n\n- `nltk < 3.9.4`\n\nPatched in:\n\n- `nltk 3.9.4`\n\nSource: https://osv.dev/vulnerability/GHSA-jm6w-m3j8-898g","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":201603,"id":"CVE-2026-33231","ts":1789399526415,"field":"exploit_available","old":"false","new":"true"},{"seq":200335,"id":"CVE-2026-33231","ts":1789397119930,"field":"exploit_available","old":"true","new":"false"},{"seq":198259,"id":"CVE-2026-33231","ts":1789391759234,"field":"exploit_available","old":"false","new":"true"},{"seq":196052,"id":"CVE-2026-33231","ts":1789383415255,"field":"exploit_available","old":"true","new":"false"},{"seq":194981,"id":"CVE-2026-33231","ts":1789380327746,"field":"exploit_available","old":"false","new":"true"},{"seq":193768,"id":"CVE-2026-33231","ts":1789378281037,"field":"exploit_available","old":"true","new":"false"},{"seq":192555,"id":"CVE-2026-33231","ts":1789376248797,"field":"exploit_available","old":"false","new":"true"},{"seq":191342,"id":"CVE-2026-33231","ts":1789373148774,"field":"exploit_available","old":"true","new":"false"},{"seq":190127,"id":"CVE-2026-33231","ts":1789369138812,"field":"exploit_available","old":"false","new":"true"},{"seq":188914,"id":"CVE-2026-33231","ts":1789368050407,"field":"exploit_available","old":"true","new":"false"},{"seq":187697,"id":"CVE-2026-33231","ts":1789365011114,"field":"exploit_available","old":"false","new":"true"},{"seq":186484,"id":"CVE-2026-33231","ts":1789363024523,"field":"exploit_available","old":"true","new":"false"},{"seq":185270,"id":"CVE-2026-33231","ts":1789360972997,"field":"exploit_available","old":"false","new":"true"},{"seq":184057,"id":"CVE-2026-33231","ts":1789357950796,"field":"exploit_available","old":"true","new":"false"},{"seq":182309,"id":"CVE-2026-33231","ts":1789354107934,"field":"exploit_available","old":"false","new":"true"},{"seq":181102,"id":"CVE-2026-33231","ts":1789352963685,"field":"exploit_available","old":"true","new":"false"},{"seq":179895,"id":"CVE-2026-33231","ts":1789350012443,"field":"exploit_available","old":"false","new":"true"},{"seq":178688,"id":"CVE-2026-33231","ts":1789347838343,"field":"exploit_available","old":"true","new":"false"},{"seq":177481,"id":"CVE-2026-33231","ts":1789346189190,"field":"exploit_available","old":"false","new":"true"},{"seq":176274,"id":"CVE-2026-33231","ts":1789342761723,"field":"exploit_available","old":"true","new":"false"},{"seq":176058,"id":"CVE-2026-33231","ts":1789342375989,"field":"exploit_available","old":"false","new":"true"},{"seq":175598,"id":"CVE-2026-33231","ts":1789338393868,"field":"exploit_available","old":"true","new":"false"},{"seq":174393,"id":"CVE-2026-33231","ts":1789334607852,"field":"exploit_available","old":"false","new":"true"},{"seq":173188,"id":"CVE-2026-33231","ts":1789333222785,"field":"exploit_available","old":"true","new":"false"},{"seq":172002,"id":"CVE-2026-33231","ts":1789330901943,"field":"exploit_available","old":"false","new":"true"},{"seq":170816,"id":"CVE-2026-33231","ts":1789328407520,"field":"exploit_available","old":"true","new":"false"},{"seq":169611,"id":"CVE-2026-33231","ts":1789326922426,"field":"exploit_available","old":"false","new":"true"},{"seq":168406,"id":"CVE-2026-33231","ts":1789323461851,"field":"exploit_available","old":"true","new":"false"},{"seq":167201,"id":"CVE-2026-33231","ts":1789319384172,"field":"exploit_available","old":"false","new":"true"},{"seq":165996,"id":"CVE-2026-33231","ts":1789318310110,"field":"exploit_available","old":"true","new":"false"},{"seq":164791,"id":"CVE-2026-33231","ts":1789315553630,"field":"exploit_available","old":"false","new":"true"},{"seq":163586,"id":"CVE-2026-33231","ts":1789313276190,"field":"exploit_available","old":"true","new":"false"},{"seq":162381,"id":"CVE-2026-33231","ts":1789311721014,"field":"exploit_available","old":"false","new":"true"},{"seq":161176,"id":"CVE-2026-33231","ts":1789308286286,"field":"exploit_available","old":"true","new":"false"},{"seq":160681,"id":"CVE-2026-33231","ts":1789304209934,"field":"exploit_available","old":"false","new":"true"},{"seq":158519,"id":"CVE-2026-33231","ts":1789299302621,"field":"exploit_available","old":"true","new":"false"},{"seq":157483,"id":"CVE-2026-33231","ts":1789296471833,"field":"exploit_available","old":"false","new":"true"},{"seq":156278,"id":"CVE-2026-33231","ts":1789294404246,"field":"exploit_available","old":"true","new":"false"},{"seq":155073,"id":"CVE-2026-33231","ts":1789292648129,"field":"exploit_available","old":"false","new":"true"},{"seq":153868,"id":"CVE-2026-33231","ts":1789289369842,"field":"exploit_available","old":"true","new":"false"},{"seq":153080,"id":"CVE-2026-33231","ts":1789285283029,"field":"exploit_available","old":"false","new":"true"},{"seq":148014,"id":"CVE-2026-33231","ts":1789270887075,"field":"exploit_available","old":"true","new":"false"},{"seq":146054,"id":"CVE-2026-33231","ts":1789269181633,"field":"exploit_available","old":"false","new":"true"},{"seq":144957,"id":"CVE-2026-33231","ts":1789266125199,"field":"exploit_available","old":"true","new":"false"},{"seq":143861,"id":"CVE-2026-33231","ts":1789262452798,"field":"exploit_available","old":"false","new":"true"},{"seq":142697,"id":"CVE-2026-33231","ts":1789261203879,"field":"exploit_available","old":"true","new":"false"},{"seq":141533,"id":"CVE-2026-33231","ts":1789258622697,"field":"exploit_available","old":"false","new":"true"},{"seq":140335,"id":"CVE-2026-33231","ts":1789256424831,"field":"exploit_available","old":"true","new":"false"},{"seq":139137,"id":"CVE-2026-33231","ts":1789254597863,"field":"exploit_available","old":"false","new":"true"},{"seq":137939,"id":"CVE-2026-33231","ts":1789251597084,"field":"exploit_available","old":"true","new":"false"}]}