Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-81723

Опубликовано: 27 авг. 2026
Источник: debian
EPSS Низкий

Описание

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to cause severe CPU consumption and denial of service through affected readers like BNCCorpusReader.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nltkfixed3.10.3-1package
nltkno-dsatrixiepackage
nltkpostponedbookwormpackage

Примечания

  • https://github.com/nltk/nltk/security/advisories/GHSA-vp2x-qp44-57v7

EPSS

Процентиль: 13%
0.00222
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
20 дней назад

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to cause severe CPU consumption and denial of service through affected readers like BNCCorpusReader.

CVSS3: 5.9
redhat
20 дней назад

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to cause severe CPU consumption and denial of service through affected readers like BNCCorpusReader.

CVSS3: 3.7
nvd
20 дней назад

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to cause severe CPU consumption and denial of service through affected readers like BNCCorpusReader.

CVSS3: 3.7
github
14 дней назад

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

EPSS

Процентиль: 13%
0.00222
Низкий