High severity7.5NVD Advisory· Published Aug 27, 2026· Updated Aug 31, 2026
CVE-2026-81722
CVE-2026-81722
Description
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' characters on every call, and _measure() invokes it for each stem position, causing O(n^2) behavior. A single ~20-50 KB untrusted token consisting of a long run of the letter 'y' followed by a matching suffix (e.g., 'ness') can pin a CPU core for seconds to minutes, causing availability impact.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nltkPyPI | < 3.10.3 | 3.10.3 |
Affected products
4- osv-coords3 versions
< 2.7.3-r27+ 2 more
- (no CPE)range: < 2.7.3-r27
- (no CPE)range: < 0.11.3-r1
- (no CPE)range: < 0.11.3-r1
Patches
Vulnerability mechanics
References
7- github.com/nltk/nltk/security/advisories/GHSA-ww6m-cw3f-q94gnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-ww6m-cw3f-q94gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-81722ghsaADVISORY
- www.vulncheck.com/advisories/nltk-porterstemmer-before-3.10.3-quadratic-time-dosnvdThird Party AdvisoryWEB
- github.com/nltk/nltk/commit/7808692d451b962711005d954859bb83aabcf8faghsaWEB
- github.com/nltk/nltk/releases/tag/v3.10.3ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3738.yamlghsaWEB
News mentions
1- Nltk Library: 16 Vulnerabilities Including Critical RCE Disclosed in BatchVypr Intelligence · Aug 27, 2026