Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-81725

Опубликовано: 27 авг. 2026
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit lazy regex patterns in the read_block method through public APIs like words() and tagged_words() to force repeated rescans and achieve near-quadratic runtime growth.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*
Версия до 3.10.3 (исключая)

EPSS

Процентиль: 14%
0.00229
Низкий

3.7 Low

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 3.7
ubuntu
20 дней назад

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit lazy regex patterns in the read_block method through public APIs like words() and tagged_words() to force repeated rescans and achieve near-quadratic runtime growth.

CVSS3: 5.9
redhat
20 дней назад

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit lazy regex patterns in the read_block method through public APIs like words() and tagged_words() to force repeated rescans and achieve near-quadratic runtime growth.

CVSS3: 3.7
debian
20 дней назад

NLTK before 3.10.3 contains a regular expression denial of service vul ...

github
8 дней назад

NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks

EPSS

Процентиль: 14%
0.00229
Низкий

3.7 Low

CVSS3

Дефекты

CWE-400
Уязвимость CVE-2026-81725