Quadratic CPU Exhaustion Vulnerability in NLTK by NLTK Developers
CVE-2026-81723
6.3MEDIUM
What is CVE-2026-81723?
NLTK is impacted by a vulnerability in the XMLCorpusView component, where improper handling of XML fragments can lead to excessive CPU utilization. This occurs when the library processes malformed XML corpus files, forcing a repetitive rescan of the data with each 1 KiB block read. Attackers can exploit this flaw, leading to significant degradation of performance and potential denial of service for applications that utilize readers such as BNCCorpusReader.
Affected Version(s)
nltk 0 < 3.10.3
nltk 3.10.3
