High severity7.5NVD Advisory· Published Aug 25, 2026· Updated Sep 1, 2026
CVE-2026-78681
CVE-2026-78681
Description
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nltkPyPI | < 3.10.3 | 3.10.3 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/nltk/nltk/security/advisories/GHSA-97qj-x29f-37w7nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-97qj-x29f-37w7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-78681ghsaADVISORY
- www.vulncheck.com/advisories/nltk-before-entity-expansion-dos-via-elementtreenvdThird Party AdvisoryWEB
- github.com/nltk/nltk/commit/e91789c9a043296ad04912ce171c22776d45963bghsaWEB
- github.com/nltk/nltk/releases/tag/v3.10.3ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3748.yamlghsaWEB
News mentions
2- Nltk Library: 16 Vulnerabilities Including Critical RCE Disclosed in BatchVypr Intelligence · Aug 27, 2026
- Nltk Library: Critical RCE and High-Severity Flaws Disclosed TogetherVypr Intelligence · Aug 25, 2026