Entity Expansion Denial of Service Vulnerability in NLTK by NLTK Project
CVE-2026-78681

8.7HIGH

Key Information:

Vendor

Nltk

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-78681?

The NLTK library, specifically versions prior to 3.10.3, utilizes the xml.etree.ElementTree module for XML parsing. This implementation inadvertently allows attackers to exploit entity declarations within document DTDs. By crafting malicious XML payloads that contain nested entity declarations, an attacker can cause significant memory consumption, leading to a denial of service condition. Organizations using NLTK must update to version 3.10.3 or later to mitigate this risk.

Affected Version(s)

nltk 0 < 3.10.3

nltk 3.10.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.