Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-80206

Опубликовано: 26 авг. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search against tree node labels without any validation or timeout. An attacker who controls the tgrep pattern (e.g., via tgrep_positions() or tgrep_compile() exposed to external input) can supply a pattern that triggers catastrophic backtracking, causing indefinite CPU saturation that blocks the Python process.

A flaw was found in NLTK, specifically within its tgrep module. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions. When processed, these expressions can cause indefinite CPU saturation, leading to a complete denial of service for the Python process utilizing the NLTK library.

Отчет

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in NLTK's tgrep module within the _tgrep_node_action function. When processing user-supplied regular expressions inside /regex/ pattern nodes via functions such as tgrep_positions() or tgrep_compile(), NLTK executes re.search without input validation or execution timeouts. If an application exposes these interfaces to unauthenticated or low-privileged attackers, supplying a specially crafted regular expression triggers catastrophic backtracking, resulting in CPU saturation and process-level denial of service.

Меры по смягчению последствий

Sanitize or restrict external input passed to NLTK's tgrep compilation functions to prevent execution of untrusted regular expressions, or enforce application-level timeouts using process isolation/multiprocessing wrappers to restrict CPU consumption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Out of support scope
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Out of support scope
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-ogx-core-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2524336nltk: NLTK: Denial of Service vulnerability in tgrep module

EPSS

Процентиль: 18%
0.00264
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
22 дня назад

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search against tree node labels without any validation or timeout. An attacker who controls the tgrep pattern (e.g., via tgrep_positions() or tgrep_compile() exposed to external input) can supply a pattern that triggers catastrophic backtracking, causing indefinite CPU saturation that blocks the Python process.

CVSS3: 5.9
nvd
22 дня назад

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search against tree node labels without any validation or timeout. An attacker who controls the tgrep pattern (e.g., via tgrep_positions() or tgrep_compile() exposed to external input) can supply a pattern that triggers catastrophic backtracking, causing indefinite CPU saturation that blocks the Python process.

CVSS3: 5.9
debian
22 дня назад

NLTK before 3.10.3 contains a regular expression denial of service (Re ...

github
9 дней назад

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

EPSS

Процентиль: 18%
0.00264
Низкий

5.9 Medium

CVSS3