{"id":"CVE-2026-81724","title":"nltk: NLTK: Denial of Service via Uncontrolled Recursion (CVE-2026-81724)","summary":"A flaw was found in NLTK. This uncontrolled recursion vulnerability in `nltk.featstruct.FeatStructReader` allows unauthenticated attackers to cause a denial of service. Attackers can achieve this by supplying deeply nested feature-structur…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-606","CWE-674"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","lightspeed_core","openshift_lightspeed","ansible_automation_platform 2","openshift_ai_rhoai","openshift_ai 3.5"],"patched":["openshift_ai 3.5"],"published":"2026-08-27","updated":"2026-09-22","sourceUpdated":"2026-09-22T05:58:51+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81724.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81724.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-81724"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2525072"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81724"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81724"},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-cw6x-m8jw-qmrh"},{"url":"https://www.vulncheck.com/advisories/nltk-before-3.10.3-denial-of-service-via-uncontrolled-recursion"},{"url":"https://access.redhat.com/errata/RHSA-2026:69539"},{"url":"https://github.com/nltk/nltk/commit/43c7b78cc8ea37e5cd3a129e27e32c415ea21cf1"},{"url":"https://github.com/nltk/nltk/releases/tag/v3.10.3"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3739.yaml"},{"url":"https://github.com/advisories/GHSA-cw6x-m8jw-qmrh"}],"tags":["csaf","vex","red-hat","ghsa","pip","score-dispute"],"epss":0.00267,"epssPercentile":0.19016,"aliases":["GHSA-cw6x-m8jw-qmrh"],"ecosystem":"pip","scores":{"vendor":7.5,"ghsa":5.3},"ingestedAt":"2026-09-02T14:45:30.430Z","slug":"CVE-2026-81724","body":"## Overview\n\nA flaw was found in NLTK. This uncontrolled recursion vulnerability in `nltk.featstruct.FeatStructReader` allows unauthenticated attackers to cause a denial of service. Attackers can achieve this by supplying deeply nested feature-structure input, which can lead to applications crashing when parsing user-supplied feature structures or feature grammars.\n\n## Vendor advisories\n\n- **RHSA-2026:69539** · Red Hat · fixed in: Red Hat OpenShift AI 3.5 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69539)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI) · no fix planned: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Lightspeed Core, OpenShift Lightspeed, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81724.json)\n\n**nltk: NLTK: Denial of Service via Uncontrolled Recursion** — rated Important by Red Hat. Released 2026-08-27, updated 2026-09-22.\n\nAffected:\n\n- Exploit Intelligence\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat Ansible Automation Platform 2\n- Red Hat OpenShift AI (RHOAI)\n\nFixed:\n\n- Red Hat OpenShift AI 3.5\n\nNo fix planned:\n\n- Exploit Intelligence\n- Red Hat Ansible Automation Platform 2\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- Red Hat OpenShift AI 3.5\n- OpenShift Lightspeed\n\n## Remediation\n\nFor Red Hat OpenShift AI 3.5.1 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:69539\n\nWorkarounds / mitigations:\n\n- Applications that process untrusted feature-structure input using NLTK should implement robust input validation and sanitization to prevent deeply nested structures from being processed by `nltk.featstruct.FeatStructReader`. If input cannot be validated, avoid processing untrusted feature-structure input with affected versions of NLTK.\n\n## Package advisory (CVE-2026-81724)\n\nAffected packages:\n\n- `nltk <= 3.10.2`\n\nPatched in:\n\n- `nltk 3.10.3`\n\nSource: https://github.com/advisories/GHSA-cw6x-m8jw-qmrh","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":202005,"id":"CVE-2026-81724","ts":1789400002166,"field":"cvss","old":"5.3","new":"7.5"},{"seq":202004,"id":"CVE-2026-81724","ts":1789400002166,"field":"severity","old":"medium","new":"high"},{"seq":200732,"id":"CVE-2026-81724","ts":1789397588109,"field":"cvss","old":"7.5","new":"5.3"},{"seq":200731,"id":"CVE-2026-81724","ts":1789397588109,"field":"severity","old":"high","new":"medium"},{"seq":199427,"id":"CVE-2026-81724","ts":1789395501920,"field":"cvss","old":"5.3","new":"7.5"},{"seq":199426,"id":"CVE-2026-81724","ts":1789395501920,"field":"severity","old":"medium","new":"high"},{"seq":198672,"id":"CVE-2026-81724","ts":1789392190514,"field":"cvss","old":"7.5","new":"5.3"},{"seq":198671,"id":"CVE-2026-81724","ts":1789392190514,"field":"severity","old":"high","new":"medium"},{"seq":197003,"id":"CVE-2026-81724","ts":1789384277261,"field":"cvss","old":"5.3","new":"7.5"},{"seq":197002,"id":"CVE-2026-81724","ts":1789384277261,"field":"severity","old":"medium","new":"high"},{"seq":196363,"id":"CVE-2026-81724","ts":1789383751675,"field":"cvss","old":"7.5","new":"5.3"},{"seq":196362,"id":"CVE-2026-81724","ts":1789383751675,"field":"severity","old":"high","new":"medium"},{"seq":195291,"id":"CVE-2026-81724","ts":1789380558918,"field":"cvss","old":"5.3","new":"7.5"},{"seq":195290,"id":"CVE-2026-81724","ts":1789380558918,"field":"severity","old":"medium","new":"high"},{"seq":194134,"id":"CVE-2026-81724","ts":1789378731008,"field":"cvss","old":"7.5","new":"5.3"},{"seq":194133,"id":"CVE-2026-81724","ts":1789378731008,"field":"severity","old":"high","new":"medium"},{"seq":192921,"id":"CVE-2026-81724","ts":1789376499803,"field":"cvss","old":"5.3","new":"7.5"},{"seq":192920,"id":"CVE-2026-81724","ts":1789376499803,"field":"severity","old":"medium","new":"high"},{"seq":191708,"id":"CVE-2026-81724","ts":1789373593147,"field":"cvss","old":"7.5","new":"5.3"},{"seq":191707,"id":"CVE-2026-81724","ts":1789373593147,"field":"severity","old":"high","new":"medium"},{"seq":190493,"id":"CVE-2026-81724","ts":1789369456521,"field":"cvss","old":"5.3","new":"7.5"},{"seq":190492,"id":"CVE-2026-81724","ts":1789369456521,"field":"severity","old":"medium","new":"high"},{"seq":189280,"id":"CVE-2026-81724","ts":1789368375720,"field":"cvss","old":"7.5","new":"5.3"},{"seq":189279,"id":"CVE-2026-81724","ts":1789368375720,"field":"severity","old":"high","new":"medium"},{"seq":188063,"id":"CVE-2026-81724","ts":1789365222628,"field":"cvss","old":"5.3","new":"7.5"},{"seq":188062,"id":"CVE-2026-81724","ts":1789365222628,"field":"severity","old":"medium","new":"high"},{"seq":186850,"id":"CVE-2026-81724","ts":1789363457150,"field":"cvss","old":"7.5","new":"5.3"},{"seq":186849,"id":"CVE-2026-81724","ts":1789363457150,"field":"severity","old":"high","new":"medium"},{"seq":185636,"id":"CVE-2026-81724","ts":1789361210091,"field":"cvss","old":"5.3","new":"7.5"},{"seq":185635,"id":"CVE-2026-81724","ts":1789361210091,"field":"severity","old":"medium","new":"high"},{"seq":184423,"id":"CVE-2026-81724","ts":1789358321220,"field":"cvss","old":"7.5","new":"5.3"},{"seq":184422,"id":"CVE-2026-81724","ts":1789358321220,"field":"severity","old":"high","new":"medium"},{"seq":182674,"id":"CVE-2026-81724","ts":1789354307928,"field":"cvss","old":"5.3","new":"7.5"},{"seq":182673,"id":"CVE-2026-81724","ts":1789354307928,"field":"severity","old":"medium","new":"high"},{"seq":181467,"id":"CVE-2026-81724","ts":1789353287164,"field":"cvss","old":"7.5","new":"5.3"},{"seq":181466,"id":"CVE-2026-81724","ts":1789353287164,"field":"severity","old":"high","new":"medium"},{"seq":180260,"id":"CVE-2026-81724","ts":1789350270371,"field":"cvss","old":"5.3","new":"7.5"},{"seq":180259,"id":"CVE-2026-81724","ts":1789350270371,"field":"severity","old":"medium","new":"high"},{"seq":179053,"id":"CVE-2026-81724","ts":1789348259334,"field":"cvss","old":"7.5","new":"5.3"},{"seq":179052,"id":"CVE-2026-81724","ts":1789348259334,"field":"severity","old":"high","new":"medium"},{"seq":177846,"id":"CVE-2026-81724","ts":1789346360675,"field":"cvss","old":"5.3","new":"7.5"},{"seq":177845,"id":"CVE-2026-81724","ts":1789346360675,"field":"severity","old":"medium","new":"high"},{"seq":176639,"id":"CVE-2026-81724","ts":1789343159559,"field":"cvss","old":"7.5","new":"5.3"},{"seq":176638,"id":"CVE-2026-81724","ts":1789343159559,"field":"severity","old":"high","new":"medium"},{"seq":174756,"id":"CVE-2026-81724","ts":1789334857647,"field":"cvss","old":"5.3","new":"7.5"},{"seq":174755,"id":"CVE-2026-81724","ts":1789334857647,"field":"severity","old":"medium","new":"high"},{"seq":173551,"id":"CVE-2026-81724","ts":1789333670483,"field":"cvss","old":"7.5","new":"5.3"},{"seq":173550,"id":"CVE-2026-81724","ts":1789333670483,"field":"severity","old":"high","new":"medium"},{"seq":172365,"id":"CVE-2026-81724","ts":1789331084689,"field":"cvss","old":"5.3","new":"7.5"},{"seq":172364,"id":"CVE-2026-81724","ts":1789331084689,"field":"severity","old":"medium","new":"high"}]}