CVE-2026-78681CWE-776
CVE-2026-78681
High · published August 25, 2026
What it is
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.
The record
Technical detail
- CVSS v3.1
- 7.5 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVSS v4.0
- 8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS
- 0.00294 · 21.7th percentile
- Weakness
- CWE-776 · Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
- Published
- 2026-08-25T06:16Z
Affected products (1)
| Product | Versions | Fixed in |
|---|
| nltk/nltk | < 3.10.3 | 3.10.3 |
References (2)
EPSS history
Timeline