CVE-2026-81722High· 7.5▾ TwilightA flaw was found in the nltk PorterStemmer component. A remote attacker could exploit this vulnerability by providing a specially crafted, untrusted token. The inefficient algorithmic complexity in the stemming process, specifically within…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
7.5 → —
high → medium
— → 7.5
medium → high
7.5 → —
high → medium
— → 7.5
medium → high
7.5 → —
high → medium
— → 7.5
medium → high
Last analysed / modified upstream
A flaw was found in the nltk PorterStemmer component. A remote attacker could exploit this vulnerability by providing a specially crafted, untrusted token. The inefficient algorithmic complexity in the stemming process, specifically within the _is_consonant() and _measure() helper functions, causes excessive CPU usage when processing certain inputs. This can lead to a denial of service (DoS) condition, where the system becomes unresponsive for an extended period.
nltk: nltk PorterStemmer: Denial of Service due to inefficient token processing — rated Important by Red Hat. Released 2026-08-27, updated 2026-09-15.
Affected:
No fix planned:
Not affected:
Will not fix
Workarounds / mitigations:
Affected packages:
nltk <= 3.10.2Patched in:
nltk 3.10.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81725Medium· 5.9nltk: NLTK: Regular Expression Denial of Service via malformed TEI blocks (CVE-2026-81725)
CVE-2026-81724High· 7.5nltk: NLTK: Denial of Service via Uncontrolled Recursion (CVE-2026-81724)
CVE-2026-79674High· 7.5nltk: NLTK: Information disclosure via path traversal in corpus-reader constructors (CVE-2026-79674)
CVE-2026-78682High· 7.5nltk: NLTK: Server-Side Request Forgery via HTTP Proxy Configuration (CVE-2026-78682)
CVE-2026-81727High· 7.1nltk: NLTK: Filesystem containment bypass allows local file overwrite (CVE-2026-81727)
CVE-2026-79675High· 8.1nltk: NLTK before 3.10.3 JVM Argument Injection via Per-Call Options (CVE-2026-79675)