CVE-2026-81725
Last modified
CVE-2026-81725 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit lazy regex patterns in the read_block method through public APIs like words() and tagged_words() to force repeated rescans and achieve near-quadratic runtime growth.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit lazy regex patterns in the read_block method through public APIs like words() and tagged_words() to force repeated rescans and achieve near-quadratic runtime growth.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| nltk | nltk | < 3.10.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-81725?
How severe is CVE-2026-81725?
How do I fix CVE-2026-81725?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8172The Simple Basic Contact Form WordPress plugin through 20250…7.1
- CVE-2026-81720openssl_encrypt before 1.4.9 fails to validate the memory_co…6.2
- CVE-2026-81721openssl_encrypt before 1.4.9 fails to validate KDF cost para…7.5
- CVE-2026-81722nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) c…7.5
- CVE-2026-81723NLTK versions before 3.10.3 contain a quadratic CPU exhausti…3.7
- CVE-2026-81724NLTK before 3.10.3 contains an uncontrolled recursion vulner…5.3
- CVE-2026-81726NLTK through 3.10.3 contains a path traversal vulnerability …7
- CVE-2026-81727NLTK versions before 3.10.3 contain a filesystem containment…7.1
- CVE-2026-81728Dolibarr before 24.0.0 contains a SQL injection in its CSV a…8.1
- CVE-2026-81729Dolibarr before 23.0.4 authorizes REST API document deletion…6.5
- CVE-2026-8173The web GUI of affected Murrelektronik Xelity switches logs …5.3
- CVE-2026-81730Dolibarr 9.0.0 through 23.0.4 saves inbound email attachment…8.2
Are you affected by CVE-2026-81725?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
