CVE-2026-78681CWE-776

CVE-2026-78681

High · published August 25, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
21.7
In the wild
Unconfirmed
What it is

NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00294 · 21.7th percentile
Weakness
CWE-776 · Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
Published
2026-08-25T06:16Z
Affected products (1)
ProductVersionsFixed in
nltk/nltk< 3.10.33.10.3
References (2)
EPSS history
Timeline
  • 26 AUG 08:27Z
    EPSS moved — → 0%
    epss
  • 25 AUG 01:30Z
    NLTK before 3.10.3 Entity Expansion DoS via ElementTree
    cvelistv5