NLTK 在 3.10.3 之前版本中存在一个不受控的递归漏洞,位于 中。未认证的攻击者可以通过提供深度嵌套的特征结构输入来触发拒绝服务(DoS)。攻击者可以构造包含超过 Python 递归限制的嵌套括号的简单载荷,从而引发未处理的 ,导致解析用户提供的特征结构或特征语法的进程崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81722 | 7.5 HIGH | nltk PorterStemmer before 3.10.3 Quadratic-time DoS |
| CVE-2026-81727 | 7.1 HIGH | NLTK before 3.10.3 Hardlink File Overwrite via downloader |
| CVE-2026-81726 | 7.0 HIGH | NLTK through 3.10.3 Path Traversal via Model-Artifact APIs |
| CVE-2026-81723 | 3.7 LOW | NLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusView |
| CVE-2026-81725 | 3.7 LOW | NLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReader |
No comments yet