{"id":"CVE-2026-81725","title":"nltk: NLTK: Regular Expression Denial of Service via malformed TEI blocks (CVE-2026-81725)","summary":"A flaw was found in NLTK, specifically within the Pl196xCorpusReader component. A remote attacker can exploit this by supplying malformed Text Encoding Initiative (TEI) blocks containing numerous unmatched opening tags. This triggers a reg…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-1333","CWE-400"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","lightspeed_core","openshift_lightspeed","ansible_automation_platform 2","openshift_ai_rhoai"],"patched":["nltk 3.10.3"],"published":"2026-08-27","updated":"2026-09-15","sourceUpdated":"2026-09-15T13:23:20+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81725.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81725.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-81725"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2525094"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81725"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81725"},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-8mpw-7fpc-4gqj"},{"url":"https://www.vulncheck.com/advisories/nltk-before-3.10.3-regular-expression-denial-of-service-via-pl196xcorpusreader"},{"url":"https://github.com/nltk/nltk/commit/7808692d451b962711005d954859bb83aabcf8fa"},{"url":"https://github.com/nltk/nltk"},{"url":"https://github.com/nltk/nltk/releases/tag/v3.10.3"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3752.yaml"},{"url":"https://github.com/advisories/GHSA-8mpw-7fpc-4gqj"}],"tags":["csaf","vex","red-hat","osv","pip","ghsa"],"epss":0.00229,"epssPercentile":0.13969,"aliases":["GHSA-8mpw-7fpc-4gqj","PYSEC-2026-3752"],"ecosystem":"pip","ingestedAt":"2026-09-02T19:31:25.161Z","slug":"CVE-2026-81725","body":"## Overview\n\nA flaw was found in NLTK, specifically within the Pl196xCorpusReader component. A remote attacker can exploit this by supplying malformed Text Encoding Initiative (TEI) blocks containing numerous unmatched opening tags. This triggers a regular expression denial of service (ReDoS) vulnerability, causing quadratic CPU consumption and leading to a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI) · no fix planned: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, … · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81725.json)\n\n**nltk: NLTK: Regular Expression Denial of Service via malformed TEI blocks** — rated Moderate by Red Hat. Released 2026-08-27, updated 2026-09-15.\n\nAffected:\n\n- Exploit Intelligence\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat Ansible Automation Platform 2\n- Red Hat OpenShift AI (RHOAI)\n\nNo fix planned:\n\n- Exploit Intelligence\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat Ansible Automation Platform 2\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- OpenShift Lightspeed\n\n## Remediation\n\nWill not fix\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-81725)\n\nAffected packages:\n\n- `nltk < 3.10.3`\n\nPatched in:\n\n- `nltk 3.10.3`\n\nSource: https://osv.dev/vulnerability/GHSA-8mpw-7fpc-4gqj","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":203872,"id":"CVE-2026-81725","ts":1789490210444,"field":"cvss","old":null,"new":"5.9"},{"seq":8250,"id":"CVE-2026-81725","ts":1788919994634,"field":"severity","old":"none","new":"medium"},{"seq":8059,"id":"CVE-2026-81725","ts":1788919280845,"field":"severity","old":"medium","new":"none"},{"seq":7868,"id":"CVE-2026-81725","ts":1788916355649,"field":"severity","old":"none","new":"medium"},{"seq":7677,"id":"CVE-2026-81725","ts":1788915297547,"field":"severity","old":"medium","new":"none"},{"seq":7486,"id":"CVE-2026-81725","ts":1788912714140,"field":"severity","old":"none","new":"medium"},{"seq":7295,"id":"CVE-2026-81725","ts":1788911331474,"field":"severity","old":"medium","new":"none"},{"seq":7099,"id":"CVE-2026-81725","ts":1788909077382,"field":"severity","old":"none","new":"medium"},{"seq":6911,"id":"CVE-2026-81725","ts":1788907391581,"field":"severity","old":"medium","new":"none"},{"seq":6713,"id":"CVE-2026-81725","ts":1788905443692,"field":"severity","old":"none","new":"medium"},{"seq":6531,"id":"CVE-2026-81725","ts":1788903459803,"field":"severity","old":"medium","new":"none"},{"seq":6422,"id":"CVE-2026-81725","ts":1788901915439,"field":"severity","old":"none","new":"medium"}]}