<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:25:48.571436+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-acronym-cve-2026-78681</id>
    <title>BREW-acronym-CVE-2026-78681 — NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses</title>
    <updated>2026-10-03T20:25:48.699572+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: acronym</p>
<p>Several XML parsing sites in NLTK still used `xml.etree.ElementTree` directly, which honours `&lt;!ENTITY&gt;` declarations in a document's internal DTD subset. A crafted document a few hundred bytes long can expand to megabytes in memory (each nesting level multiplies by ten), a denial-of-service.</p>
<p>Affected call sites (&lt;= 3.10.2):
- `nltk.chunk.named_entity.load_ace_file` — parses ACE annotation XML
- `nltk.internals.ElementWrapper` — converts any given string to an Element
- `nltk.downloader` — `Package.fromxml`, `Collection.fromxml`, `_find_collections`, `_find_packages`</p>
<p>libexpat 2.6.0 added an input-amplification cap, but it only engages above an activation threshold (~8 MiB output) and depends on whichever libexpat the interpreter links; builds against older libexpat have no cap at all. External entities are not resolved by ElementTree, so this is a memory-amplification DoS (CWE-776), not XXE/file disclosure.</p>
<p>This completes the earlier defusedxml adoption that these sites were missed by. Fix routes all of them through a new `nltk.xmlsec` module that refuses entity declarations, preferring `defusedxml` and falling back to a standard-library `xml.parsers.expat` pre-scan when defusedxml is absent.</p>
<p>---</p>
<p>## Attack demonstration</p>
<p>Reproducible PoC against a real affected entry point (`nltk.internals.ElementWrapper`). Every number below is captured output, not illustrative.</p>
<p>### 1. The amplification (vulnerable path: raw `xml.etree.ElementTree`)</p>
<p>A payload of a few hundred bytes e…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-acronym-cve-2026-78681"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-359340</id>
    <title>EUVD-2026-359340</title>
    <updated>2026-10-03T20:25:48.699657+00:00</updated>
    <content>EUVD-2026-359340</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-359340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-78681</id>
    <title>fkie_cve-2026-78681</title>
    <updated>2026-10-03T20:25:48.699674+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-78681"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-97qj-x29f-37w7</id>
    <title>GHSA-97qj-x29f-37w7 — NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses</title>
    <updated>2026-10-03T20:25:48.699698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: nltk</p>
<p>Several XML parsing sites in NLTK still used `xml.etree.ElementTree` directly, which honours `&lt;!ENTITY&gt;` declarations in a document's internal DTD subset. A crafted document a few hundred bytes long can expand to megabytes in memory (each nesting level multiplies by ten), a denial-of-service.</p>
<p>Affected call sites (&lt;= 3.10.2):
- `nltk.chunk.named_entity.load_ace_file` — parses ACE annotation XML
- `nltk.internals.ElementWrapper` — converts any given string to an Element
- `nltk.downloader` — `Package.fromxml`, `Collection.fromxml`, `_find_collections`, `_find_packages`</p>
<p>libexpat 2.6.0 added an input-amplification cap, but it only engages above an activation threshold (~8 MiB output) and depends on whichever libexpat the interpreter links; builds against older libexpat have no cap at all. External entities are not resolved by ElementTree, so this is a memory-amplification DoS (CWE-776), not XXE/file disclosure.</p>
<p>This completes the earlier defusedxml adoption that these sites were missed by. Fix routes all of them through a new `nltk.xmlsec` module that refuses entity declarations, preferring `defusedxml` and falling back to a standard-library `xml.parsers.expat` pre-scan when defusedxml is absent.</p>
<p>---</p>
<p>## Attack demonstration</p>
<p>Reproducible PoC against a real affected entry point (`nltk.internals.ElementWrapper`). Every number below is captured output, not illustrative.</p>
<p>### 1. The amplification (vulnerable path: raw `xml.etree.ElementTree`)</p>
<p>A payload of a few hundred bytes e…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-97qj-x29f-37w7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3748</id>
    <title>PYSEC-2026-3748</title>
    <updated>2026-10-03T20:25:48.699747+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: nltk</p>
<p>NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3748"/>
  </entry>
</feed>
