{"id":"CVE-2026-80205","title":"nltk: NLTK: Denial of Service via unvalidated regular expressions (CVE-2026-80205)","summary":"A flaw was found in NLTK. A remote attacker can exploit a regular expression denial of service (ReDoS) vulnerability in the `Text.findall()` and `TokenSearcher.findall()` methods. These methods accept user-supplied regular expressions with…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-1333","vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","lightspeed_core","openshift_lightspeed","ansible_automation_platform 2","openshift_ai_rhoai"],"patched":["nltk 3.10.0"],"published":"2026-08-26","updated":"2026-09-15","sourceUpdated":"2026-09-15T13:22:12+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80205.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80205.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80205"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2524331"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80205"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80205"},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-rrv8-h7p8-rx55"},{"url":"https://www.vulncheck.com/advisories/nltk-before-3.10.0-redos-via-text-findall-unvalidated-regex"},{"url":"https://github.com/nltk/nltk/pull/3674"},{"url":"https://github.com/nltk/nltk/commit/d8e47539317b571ab1422981f5b9653d5eae1249"},{"url":"https://github.com/nltk/nltk"},{"url":"https://github.com/nltk/nltk/releases/tag/v3.10.0"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3750.yaml"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/01/3"},{"url":"https://github.com/advisories/GHSA-rrv8-h7p8-rx55"}],"tags":["csaf","vex","red-hat","osv","pip","ghsa"],"epss":0.00489,"epssPercentile":0.41055,"aliases":["GHSA-rrv8-h7p8-rx55","PYSEC-2026-3750"],"ecosystem":"pip","ingestedAt":"2026-09-02T19:31:25.079Z","slug":"CVE-2026-80205","body":"## Overview\n\nA flaw was found in NLTK. A remote attacker can exploit a regular expression denial of service (ReDoS) vulnerability in the `Text.findall()` and `TokenSearcher.findall()` methods. These methods accept user-supplied regular expressions without validation, allowing an attacker to provide crafted patterns that cause catastrophic backtracking. This can lead to indefinite CPU saturation, resulting in a denial of service to all users of the Python process.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI) · no fix planned: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Lightspeed Core, OpenShift Lightspeed, … · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80205.json)\n\n**nltk: NLTK: Denial of Service via unvalidated regular expressions** — rated Important by Red Hat. Released 2026-08-26, updated 2026-09-15.\n\nAffected:\n\n- Exploit Intelligence\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat Ansible Automation Platform 2\n- Red Hat OpenShift AI (RHOAI)\n\nNo fix planned:\n\n- Exploit Intelligence\n- Red Hat Ansible Automation Platform 2\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- OpenShift Lightspeed\n\n## Remediation\n\nWill not fix\n\nWorkarounds / mitigations:\n\n- Sanitize all untrusted input passed to `Text.findall()` or `TokenSearcher.findall()` to prevent execution of arbitrary or unvalidated regular expressions, or enforce execution timeouts via worker process isolation to bound CPU consumption.\n\n## Package advisory (CVE-2026-80205)\n\nAffected packages:\n\n- `nltk < 3.10.0`\n\nPatched in:\n\n- `nltk 3.10.0`\n\nSource: https://osv.dev/vulnerability/GHSA-rrv8-h7p8-rx55","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":8231,"id":"CVE-2026-80205","ts":1788919993782,"field":"cvss","old":null,"new":"7.5"},{"seq":8230,"id":"CVE-2026-80205","ts":1788919993782,"field":"severity","old":"none","new":"high"},{"seq":8040,"id":"CVE-2026-80205","ts":1788919280764,"field":"cvss","old":"7.5","new":null},{"seq":8039,"id":"CVE-2026-80205","ts":1788919280764,"field":"severity","old":"high","new":"none"},{"seq":7849,"id":"CVE-2026-80205","ts":1788916354392,"field":"cvss","old":null,"new":"7.5"},{"seq":7848,"id":"CVE-2026-80205","ts":1788916354392,"field":"severity","old":"none","new":"high"},{"seq":7658,"id":"CVE-2026-80205","ts":1788915297466,"field":"cvss","old":"7.5","new":null},{"seq":7657,"id":"CVE-2026-80205","ts":1788915297466,"field":"severity","old":"high","new":"none"},{"seq":7467,"id":"CVE-2026-80205","ts":1788912713843,"field":"cvss","old":null,"new":"7.5"},{"seq":7466,"id":"CVE-2026-80205","ts":1788912713843,"field":"severity","old":"none","new":"high"},{"seq":7276,"id":"CVE-2026-80205","ts":1788911331395,"field":"cvss","old":"7.5","new":null},{"seq":7275,"id":"CVE-2026-80205","ts":1788911331395,"field":"severity","old":"high","new":"none"},{"seq":7080,"id":"CVE-2026-80205","ts":1788909077080,"field":"cvss","old":null,"new":"7.5"},{"seq":7079,"id":"CVE-2026-80205","ts":1788909077080,"field":"severity","old":"none","new":"high"},{"seq":6892,"id":"CVE-2026-80205","ts":1788907391499,"field":"cvss","old":"7.5","new":null},{"seq":6891,"id":"CVE-2026-80205","ts":1788907391499,"field":"severity","old":"high","new":"none"},{"seq":6694,"id":"CVE-2026-80205","ts":1788905443418,"field":"cvss","old":null,"new":"7.5"},{"seq":6693,"id":"CVE-2026-80205","ts":1788905443418,"field":"severity","old":"none","new":"high"},{"seq":6512,"id":"CVE-2026-80205","ts":1788903459722,"field":"cvss","old":"7.5","new":null},{"seq":6511,"id":"CVE-2026-80205","ts":1788903459722,"field":"severity","old":"high","new":"none"},{"seq":6425,"id":"CVE-2026-80205","ts":1788901915453,"field":"cvss","old":null,"new":"7.5"},{"seq":6424,"id":"CVE-2026-80205","ts":1788901915453,"field":"severity","old":"none","new":"high"}]}