https://seclists.org/oss-sec/2026/q3/634: CVE-2026-80205 : DoS in NLTK Text.findall() (CVSS 8.7 High)
Published Sep 1, 2026
·Updated
Affected Software
1 affected component
NLTK<=3.9.4
Frequently Asked Questions
1
Which deployments are exposed?
Deployments using NLTK versions 3.9.4 or earlier are affected if they call Text.findall() or TokenSearcher.findall() with regex patterns supplied by users.
2
What level of attacker control is required?
An attacker needs to provide a regex pattern that reaches one of the affected findall() methods. Patterns with nested quantifiers can trigger catastrophic backtracking in Python's re engine.
3
What is the operational impact of successful exploitation?
The regex evaluation can consume CPU through exponential state enumeration, pinning the process and potentially causing it to hang indefinitely.
4
What should be done if this functionality is in use?
Upgrade NLTK to version 3.10.0, which contains the fix. The affected versions are NLTK 3.9.4 and earlier.