VYPR
Medium severity5.3NVD Advisory· Published Aug 27, 2026

CVE-2026-81724

CVE-2026-81724

Description

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets that exceed Python's recursion limit and raise an unhandled RecursionError, crashing applications that parse user-supplied feature structures or feature grammars.

Affected products

2
  • Nltk/Nltkinferred2 versions
    <3.10.3+ 1 more
    • (no CPE)range: <3.10.3
    • (no CPE)range: <3.10.3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.