{"id":"CVE-2026-81722","title":"nltk: nltk PorterStemmer: Denial of Service due to inefficient token processing (CVE-2026-81722)","summary":"A flaw was found in the nltk PorterStemmer component. A remote attacker could exploit this vulnerability by providing a specially crafted, untrusted token. The inefficient algorithmic complexity in the stemming process, specifically within…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-606","CWE-407"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","lightspeed_core","openshift_lightspeed","ansible_automation_platform 2","openshift_ai_rhoai","openshift_ai 3.5"],"patched":["openshift_ai 3.5"],"published":"2026-08-27","updated":"2026-09-22","sourceUpdated":"2026-09-22T05:58:46+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81722.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81722.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-81722"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2525085"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81722"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81722"},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-ww6m-cw3f-q94g"},{"url":"https://www.vulncheck.com/advisories/nltk-porterstemmer-before-3.10.3-quadratic-time-dos"},{"url":"https://access.redhat.com/errata/RHSA-2026:69539"},{"url":"https://github.com/nltk/nltk/commit/7808692d451b962711005d954859bb83aabcf8fa"},{"url":"https://github.com/nltk/nltk/releases/tag/v3.10.3"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3738.yaml"},{"url":"https://github.com/advisories/GHSA-ww6m-cw3f-q94g"}],"tags":["csaf","vex","red-hat","ghsa","pip"],"epss":0.00363,"epssPercentile":0.30059,"aliases":["GHSA-ww6m-cw3f-q94g"],"ecosystem":"pip","ingestedAt":"2026-09-02T14:45:30.224Z","slug":"CVE-2026-81722","body":"## Overview\n\nA flaw was found in the nltk PorterStemmer component. A remote attacker could exploit this vulnerability by providing a specially crafted, untrusted token. The inefficient algorithmic complexity in the stemming process, specifically within the _is_consonant() and _measure() helper functions, causes excessive CPU usage when processing certain inputs. This can lead to a denial of service (DoS) condition, where the system becomes unresponsive for an extended period.\n\n## Vendor advisories\n\n- **RHSA-2026:69539** · Red Hat · fixed in: Red Hat OpenShift AI 3.5 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69539)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI) · no fix planned: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Lightspeed Core, OpenShift Lightspeed, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81722.json)\n\n**nltk: nltk PorterStemmer: Denial of Service due to inefficient token processing** — rated Important by Red Hat. Released 2026-08-27, updated 2026-09-22.\n\nAffected:\n\n- Exploit Intelligence\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat Ansible Automation Platform 2\n- Red Hat OpenShift AI (RHOAI)\n\nFixed:\n\n- Red Hat OpenShift AI 3.5\n\nNo fix planned:\n\n- Exploit Intelligence\n- Red Hat Ansible Automation Platform 2\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- Red Hat OpenShift AI 3.5\n- OpenShift Lightspeed\n\n## Remediation\n\nFor Red Hat OpenShift AI 3.5.1 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:69539\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-81722)\n\nAffected packages:\n\n- `nltk <= 3.10.2`\n\nPatched in:\n\n- `nltk 3.10.3`\n\nSource: https://github.com/advisories/GHSA-ww6m-cw3f-q94g","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":202002,"id":"CVE-2026-81722","ts":1789400002151,"field":"cvss","old":null,"new":"7.5"},{"seq":202001,"id":"CVE-2026-81722","ts":1789400002151,"field":"severity","old":"medium","new":"high"},{"seq":200729,"id":"CVE-2026-81722","ts":1789397588094,"field":"cvss","old":"7.5","new":null},{"seq":200728,"id":"CVE-2026-81722","ts":1789397588094,"field":"severity","old":"high","new":"medium"},{"seq":199424,"id":"CVE-2026-81722","ts":1789395501906,"field":"cvss","old":null,"new":"7.5"},{"seq":199423,"id":"CVE-2026-81722","ts":1789395501906,"field":"severity","old":"medium","new":"high"},{"seq":198669,"id":"CVE-2026-81722","ts":1789392190500,"field":"cvss","old":"7.5","new":null},{"seq":198668,"id":"CVE-2026-81722","ts":1789392190500,"field":"severity","old":"high","new":"medium"},{"seq":197000,"id":"CVE-2026-81722","ts":1789384277248,"field":"cvss","old":null,"new":"7.5"},{"seq":196999,"id":"CVE-2026-81722","ts":1789384277248,"field":"severity","old":"medium","new":"high"},{"seq":196360,"id":"CVE-2026-81722","ts":1789383751658,"field":"cvss","old":"7.5","new":null},{"seq":196359,"id":"CVE-2026-81722","ts":1789383751658,"field":"severity","old":"high","new":"medium"},{"seq":195288,"id":"CVE-2026-81722","ts":1789380558904,"field":"cvss","old":null,"new":"7.5"},{"seq":195287,"id":"CVE-2026-81722","ts":1789380558904,"field":"severity","old":"medium","new":"high"},{"seq":194131,"id":"CVE-2026-81722","ts":1789378730734,"field":"cvss","old":"7.5","new":null},{"seq":194130,"id":"CVE-2026-81722","ts":1789378730734,"field":"severity","old":"high","new":"medium"},{"seq":192918,"id":"CVE-2026-81722","ts":1789376499790,"field":"cvss","old":null,"new":"7.5"},{"seq":192917,"id":"CVE-2026-81722","ts":1789376499790,"field":"severity","old":"medium","new":"high"},{"seq":191705,"id":"CVE-2026-81722","ts":1789373593118,"field":"cvss","old":"7.5","new":null},{"seq":191704,"id":"CVE-2026-81722","ts":1789373593118,"field":"severity","old":"high","new":"medium"},{"seq":190490,"id":"CVE-2026-81722","ts":1789369456505,"field":"cvss","old":null,"new":"7.5"},{"seq":190489,"id":"CVE-2026-81722","ts":1789369456505,"field":"severity","old":"medium","new":"high"},{"seq":189277,"id":"CVE-2026-81722","ts":1789368375705,"field":"cvss","old":"7.5","new":null},{"seq":189276,"id":"CVE-2026-81722","ts":1789368375705,"field":"severity","old":"high","new":"medium"},{"seq":188060,"id":"CVE-2026-81722","ts":1789365222615,"field":"cvss","old":null,"new":"7.5"},{"seq":188059,"id":"CVE-2026-81722","ts":1789365222615,"field":"severity","old":"medium","new":"high"},{"seq":186847,"id":"CVE-2026-81722","ts":1789363457136,"field":"cvss","old":"7.5","new":null},{"seq":186846,"id":"CVE-2026-81722","ts":1789363457136,"field":"severity","old":"high","new":"medium"},{"seq":185633,"id":"CVE-2026-81722","ts":1789361210076,"field":"cvss","old":null,"new":"7.5"},{"seq":185632,"id":"CVE-2026-81722","ts":1789361210076,"field":"severity","old":"medium","new":"high"},{"seq":184420,"id":"CVE-2026-81722","ts":1789358321204,"field":"cvss","old":"7.5","new":null},{"seq":184419,"id":"CVE-2026-81722","ts":1789358321204,"field":"severity","old":"high","new":"medium"},{"seq":182671,"id":"CVE-2026-81722","ts":1789354307915,"field":"cvss","old":null,"new":"7.5"},{"seq":182670,"id":"CVE-2026-81722","ts":1789354307915,"field":"severity","old":"medium","new":"high"},{"seq":181464,"id":"CVE-2026-81722","ts":1789353286898,"field":"cvss","old":"7.5","new":null},{"seq":181463,"id":"CVE-2026-81722","ts":1789353286898,"field":"severity","old":"high","new":"medium"},{"seq":180257,"id":"CVE-2026-81722","ts":1789350270357,"field":"cvss","old":null,"new":"7.5"},{"seq":180256,"id":"CVE-2026-81722","ts":1789350270357,"field":"severity","old":"medium","new":"high"},{"seq":179050,"id":"CVE-2026-81722","ts":1789348259320,"field":"cvss","old":"7.5","new":null},{"seq":179049,"id":"CVE-2026-81722","ts":1789348259320,"field":"severity","old":"high","new":"medium"},{"seq":177843,"id":"CVE-2026-81722","ts":1789346360661,"field":"cvss","old":null,"new":"7.5"},{"seq":177842,"id":"CVE-2026-81722","ts":1789346360661,"field":"severity","old":"medium","new":"high"},{"seq":176636,"id":"CVE-2026-81722","ts":1789343159544,"field":"cvss","old":"7.5","new":null},{"seq":176635,"id":"CVE-2026-81722","ts":1789343159544,"field":"severity","old":"high","new":"medium"},{"seq":174753,"id":"CVE-2026-81722","ts":1789334857633,"field":"cvss","old":null,"new":"7.5"},{"seq":174752,"id":"CVE-2026-81722","ts":1789334857633,"field":"severity","old":"medium","new":"high"},{"seq":173548,"id":"CVE-2026-81722","ts":1789333670469,"field":"cvss","old":"7.5","new":null},{"seq":173547,"id":"CVE-2026-81722","ts":1789333670469,"field":"severity","old":"high","new":"medium"},{"seq":172362,"id":"CVE-2026-81722","ts":1789331084676,"field":"cvss","old":null,"new":"7.5"},{"seq":172361,"id":"CVE-2026-81722","ts":1789331084676,"field":"severity","old":"medium","new":"high"}]}