GHSA-ff5c-cp5c-9wjf: Pip/nltk vulnerability

Published Sep 2, 2026
·
Updated

nltk.parse.RecursiveDescentParser (and SteppingRecursiveDescentParser) enumerate parses top-down with no bound on the number of recursive steps. A small, crafted context-free grammar makes a short input consume unbounded CPU (and/or exhaust the Python recursion stack), pinning a process indefinitely — a denial of service.

Proof of concept

Both of the following hang on a 24-token input (killed after 8s; growth is super-linear in input length), on NLTK develop:

python from nltk import CFG from nltk.parse import RecursiveDescentParser

(a) left recursion -> unbounded recursion g = CFG.fromstring("S -> S S | 'a'") list(RecursiveDescentParser(g).parse(["a"] 24)) # hangs

(b) ambiguous grammar -> exponential number of parses g = CFG.fromstring("S -> 'a' S | 'a' S S | 'a'") list(RecursiveDescentParser(g).parse(["a"] 24)) # hangs

Impact

An application that runs RecursiveDescentParser on a grammar (or an input) drawn from an untrusted source can be driven into an unbounded CPU / stack-exhaustion loop by a tiny payload. No confidentiality or integrity impact; single-process availability only.

Sibling

The RegexpTokenizer ReDoS reported alongside this (CVE-2026-12875) is a different class (caller-supplied regex) and is addressed under GHSA-w3v8-gmh9-3wv7.

Affected Software

1 affected componentFixes available
pip/nltk<=3.10.2
3.10.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/nltk to a version that resolves this vulnerability.

    Fixed in 3.10.3

Event History

Sep 2, 2026
Advisory Published
via GitHub·02:33 PM
Data Sourced
via GitHub·02:33 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which applications are realistically exposed to this denial of service?

Applications are exposed when they run RecursiveDescentParser or SteppingRecursiveDescentParser using a grammar or input obtained from an untrusted source. The impact is limited to availability of the affected process; no confidentiality or integrity impact is described.

2

What does an attacker need to trigger the issue?

An attacker needs to supply a crafted context-free grammar or input that causes unbounded recursive parsing or an exponential number of parses. The provided examples use a 24-token input with either left-recursive or highly ambiguous grammar rules.

3

What can happen if the parser is exploited?

The parser can consume unbounded CPU and pin the process indefinitely, or exhaust the Python recursion stack. This is a single-process denial of service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203