Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    BREW-ACRONYM-CVE-2026-12876 (GHSA-FF5C-CP5C-9WJF)

    Vulnerability from osv_homebrew – Published: 2026-09-03 08:45 – Updated: 2026-09-17 18:47 – Source website
    VLAI
    Summary
    NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
    Details

    nltk.parse.RecursiveDescentParser (and SteppingRecursiveDescentParser) enumerate parses top-down with no bound on the number of recursive steps. A small, crafted context-free grammar makes a short input consume unbounded CPU (and/or exhaust the Python recursion stack), pinning a process indefinitely — a denial of service.

    Proof of concept

    Both of the following hang on a 24-token input (killed after 8s; growth is super-linear in input length), on NLTK develop:

    from nltk import CFG
    from nltk.parse import RecursiveDescentParser
    
    # (a) left recursion -> unbounded recursion
    g = CFG.fromstring("S -> S S | 'a'")
    list(RecursiveDescentParser(g).parse(["a"] * 24))   # hangs
    
    # (b) ambiguous grammar -> exponential number of parses
    g = CFG.fromstring("S -> 'a' S | 'a' S S | 'a'")
    list(RecursiveDescentParser(g).parse(["a"] * 24))   # hangs
    

    Impact

    An application that runs RecursiveDescentParser on a grammar (or an input) drawn from an untrusted source can be driven into an unbounded CPU / stack-exhaustion loop by a tiny payload. No confidentiality or integrity impact; single-process availability only.

    Sibling

    The RegexpTokenizer ReDoS reported alongside this (CVE-2026-12875) is a different class (caller-supplied regex) and is addressed under GHSA-w3v8-gmh9-3wv7.


    {
      "affected": [
        {
          "ecosystem_specific": {
            "fix": "bump",
            "range_state": "fixed",
            "resource": "nltk",
            "resource_purl": "pkg:pypi/nltk@3.10.3",
            "upstream_fixed_in": "3.10.3"
          },
          "package": {
            "ecosystem": "Homebrew",
            "name": "acronym",
            "purl": "pkg:brew/acronym"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "2.0.0"
                },
                {
                  "fixed": "2.0.0_5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "confidence": "high",
        "source": "matched",
        "strategy": "registry",
        "upstream_evidence": [
          {
            "ecosystem": "PyPI",
            "key": "pkg:pypi/nltk@3.10.3",
            "name": "nltk",
            "resource": "nltk",
            "strategy": "registry",
            "subject_version": "3.10.3"
          }
        ]
      },
      "details": "`nltk.parse.RecursiveDescentParser` (and `SteppingRecursiveDescentParser`) enumerate parses top-down with no bound on the number of recursive steps. A small, crafted context-free grammar makes a short input consume unbounded CPU (and/or exhaust the Python recursion stack), pinning a process indefinitely \u2014 a denial of service.\n\n## Proof of concept\n\nBoth of the following hang on a 24-token input (killed after 8s; growth is super-linear in input length), on NLTK develop:\n\n```python\nfrom nltk import CFG\nfrom nltk.parse import RecursiveDescentParser\n\n# (a) left recursion -\u003e unbounded recursion\ng = CFG.fromstring(\"S -\u003e S S | \u0027a\u0027\")\nlist(RecursiveDescentParser(g).parse([\"a\"] * 24))   # hangs\n\n# (b) ambiguous grammar -\u003e exponential number of parses\ng = CFG.fromstring(\"S -\u003e \u0027a\u0027 S | \u0027a\u0027 S S | \u0027a\u0027\")\nlist(RecursiveDescentParser(g).parse([\"a\"] * 24))   # hangs\n```\n\n## Impact\n\nAn application that runs `RecursiveDescentParser` on a grammar (or an input) drawn from an untrusted source can be driven into an unbounded CPU / stack-exhaustion loop by a tiny payload. No confidentiality or integrity impact; single-process availability only.\n\n## Sibling\n\nThe RegexpTokenizer ReDoS reported alongside this (CVE-2026-12875) is a different class (caller-supplied regex) and is addressed under GHSA-w3v8-gmh9-3wv7.",
      "id": "BREW-acronym-CVE-2026-12876",
      "modified": "2026-09-17T18:47:55Z",
      "published": "2026-09-03T08:45:00Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/security/advisories/GHSA-ff5c-cp5c-9wjf"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/pull/3649"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/commit/43aaca1b9024138421c97f970bf13ee19ac8129d"
        },
        {
          "type": "PACKAGE",
          "url": "https://github.com/nltk/nltk"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/releases/tag/v3.10.3"
        }
      ],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
          "type": "CVSS_V4"
        }
      ],
      "summary": "NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars",
      "upstream": [
        "GHSA-ff5c-cp5c-9wjf",
        "CVE-2026-12876",
        "PYSEC-2026-3869"
      ]
    }

    BREW-GPTLINE-CVE-2026-12876 (GHSA-FF5C-CP5C-9WJF)

    Vulnerability from osv_homebrew – Published: 2026-09-03 09:08 – Updated: 2026-09-17 19:32 – Source website
    VLAI
    Summary
    NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
    Details

    nltk.parse.RecursiveDescentParser (and SteppingRecursiveDescentParser) enumerate parses top-down with no bound on the number of recursive steps. A small, crafted context-free grammar makes a short input consume unbounded CPU (and/or exhaust the Python recursion stack), pinning a process indefinitely — a denial of service.

    Proof of concept

    Both of the following hang on a 24-token input (killed after 8s; growth is super-linear in input length), on NLTK develop:

    from nltk import CFG
    from nltk.parse import RecursiveDescentParser
    
    # (a) left recursion -> unbounded recursion
    g = CFG.fromstring("S -> S S | 'a'")
    list(RecursiveDescentParser(g).parse(["a"] * 24))   # hangs
    
    # (b) ambiguous grammar -> exponential number of parses
    g = CFG.fromstring("S -> 'a' S | 'a' S S | 'a'")
    list(RecursiveDescentParser(g).parse(["a"] * 24))   # hangs
    

    Impact

    An application that runs RecursiveDescentParser on a grammar (or an input) drawn from an untrusted source can be driven into an unbounded CPU / stack-exhaustion loop by a tiny payload. No confidentiality or integrity impact; single-process availability only.

    Sibling

    The RegexpTokenizer ReDoS reported alongside this (CVE-2026-12875) is a different class (caller-supplied regex) and is addressed under GHSA-w3v8-gmh9-3wv7.


    {
      "affected": [
        {
          "ecosystem_specific": {
            "fix": "bump",
            "range_state": "fixed",
            "resource": "nltk",
            "resource_purl": "pkg:pypi/nltk@3.10.3",
            "upstream_fixed_in": "3.10.3"
          },
          "package": {
            "ecosystem": "Homebrew",
            "name": "gptline",
            "purl": "pkg:brew/gptline"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "1.0.8"
                },
                {
                  "fixed": "1.0.8_23"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "confidence": "high",
        "source": "matched",
        "strategy": "registry",
        "upstream_evidence": [
          {
            "ecosystem": "PyPI",
            "key": "pkg:pypi/nltk@3.10.3",
            "name": "nltk",
            "resource": "nltk",
            "strategy": "registry",
            "subject_version": "3.10.3"
          }
        ]
      },
      "details": "`nltk.parse.RecursiveDescentParser` (and `SteppingRecursiveDescentParser`) enumerate parses top-down with no bound on the number of recursive steps. A small, crafted context-free grammar makes a short input consume unbounded CPU (and/or exhaust the Python recursion stack), pinning a process indefinitely \u2014 a denial of service.\n\n## Proof of concept\n\nBoth of the following hang on a 24-token input (killed after 8s; growth is super-linear in input length), on NLTK develop:\n\n```python\nfrom nltk import CFG\nfrom nltk.parse import RecursiveDescentParser\n\n# (a) left recursion -\u003e unbounded recursion\ng = CFG.fromstring(\"S -\u003e S S | \u0027a\u0027\")\nlist(RecursiveDescentParser(g).parse([\"a\"] * 24))   # hangs\n\n# (b) ambiguous grammar -\u003e exponential number of parses\ng = CFG.fromstring(\"S -\u003e \u0027a\u0027 S | \u0027a\u0027 S S | \u0027a\u0027\")\nlist(RecursiveDescentParser(g).parse([\"a\"] * 24))   # hangs\n```\n\n## Impact\n\nAn application that runs `RecursiveDescentParser` on a grammar (or an input) drawn from an untrusted source can be driven into an unbounded CPU / stack-exhaustion loop by a tiny payload. No confidentiality or integrity impact; single-process availability only.\n\n## Sibling\n\nThe RegexpTokenizer ReDoS reported alongside this (CVE-2026-12875) is a different class (caller-supplied regex) and is addressed under GHSA-w3v8-gmh9-3wv7.",
      "id": "BREW-gptline-CVE-2026-12876",
      "modified": "2026-09-17T19:32:01Z",
      "published": "2026-09-03T09:08:38Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/security/advisories/GHSA-ff5c-cp5c-9wjf"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/pull/3649"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/commit/43aaca1b9024138421c97f970bf13ee19ac8129d"
        },
        {
          "type": "PACKAGE",
          "url": "https://github.com/nltk/nltk"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/releases/tag/v3.10.3"
        }
      ],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
          "type": "CVSS_V4"
        }
      ],
      "summary": "NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars",
      "upstream": [
        "GHSA-ff5c-cp5c-9wjf",
        "CVE-2026-12876",
        "PYSEC-2026-3869"
      ]
    }

    BREW-SAFETY-CVE-2026-12876 (GHSA-FF5C-CP5C-9WJF)

    Vulnerability from osv_homebrew – Published: 2026-09-03 10:05 – Updated: 2026-09-17 17:35 – Source website
    VLAI
    Summary
    NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
    Details

    nltk.parse.RecursiveDescentParser (and SteppingRecursiveDescentParser) enumerate parses top-down with no bound on the number of recursive steps. A small, crafted context-free grammar makes a short input consume unbounded CPU (and/or exhaust the Python recursion stack), pinning a process indefinitely — a denial of service.

    Proof of concept

    Both of the following hang on a 24-token input (killed after 8s; growth is super-linear in input length), on NLTK develop:

    from nltk import CFG
    from nltk.parse import RecursiveDescentParser
    
    # (a) left recursion -> unbounded recursion
    g = CFG.fromstring("S -> S S | 'a'")
    list(RecursiveDescentParser(g).parse(["a"] * 24))   # hangs
    
    # (b) ambiguous grammar -> exponential number of parses
    g = CFG.fromstring("S -> 'a' S | 'a' S S | 'a'")
    list(RecursiveDescentParser(g).parse(["a"] * 24))   # hangs
    

    Impact

    An application that runs RecursiveDescentParser on a grammar (or an input) drawn from an untrusted source can be driven into an unbounded CPU / stack-exhaustion loop by a tiny payload. No confidentiality or integrity impact; single-process availability only.

    Sibling

    The RegexpTokenizer ReDoS reported alongside this (CVE-2026-12875) is a different class (caller-supplied regex) and is addressed under GHSA-w3v8-gmh9-3wv7.


    {
      "affected": [
        {
          "ecosystem_specific": {
            "fix": "bump",
            "range_state": "fixed",
            "resource": "nltk",
            "resource_purl": "pkg:pypi/nltk@3.10.3",
            "upstream_fixed_in": "3.10.3"
          },
          "package": {
            "ecosystem": "Homebrew",
            "name": "safety",
            "purl": "pkg:brew/safety"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "3.3.1"
                },
                {
                  "fixed": "3.8.1_2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "confidence": "high",
        "source": "matched",
        "strategy": "registry",
        "upstream_evidence": [
          {
            "ecosystem": "PyPI",
            "key": "pkg:pypi/nltk@3.10.3",
            "name": "nltk",
            "resource": "nltk",
            "strategy": "registry",
            "subject_version": "3.10.3"
          }
        ]
      },
      "details": "`nltk.parse.RecursiveDescentParser` (and `SteppingRecursiveDescentParser`) enumerate parses top-down with no bound on the number of recursive steps. A small, crafted context-free grammar makes a short input consume unbounded CPU (and/or exhaust the Python recursion stack), pinning a process indefinitely \u2014 a denial of service.\n\n## Proof of concept\n\nBoth of the following hang on a 24-token input (killed after 8s; growth is super-linear in input length), on NLTK develop:\n\n```python\nfrom nltk import CFG\nfrom nltk.parse import RecursiveDescentParser\n\n# (a) left recursion -\u003e unbounded recursion\ng = CFG.fromstring(\"S -\u003e S S | \u0027a\u0027\")\nlist(RecursiveDescentParser(g).parse([\"a\"] * 24))   # hangs\n\n# (b) ambiguous grammar -\u003e exponential number of parses\ng = CFG.fromstring(\"S -\u003e \u0027a\u0027 S | \u0027a\u0027 S S | \u0027a\u0027\")\nlist(RecursiveDescentParser(g).parse([\"a\"] * 24))   # hangs\n```\n\n## Impact\n\nAn application that runs `RecursiveDescentParser` on a grammar (or an input) drawn from an untrusted source can be driven into an unbounded CPU / stack-exhaustion loop by a tiny payload. No confidentiality or integrity impact; single-process availability only.\n\n## Sibling\n\nThe RegexpTokenizer ReDoS reported alongside this (CVE-2026-12875) is a different class (caller-supplied regex) and is addressed under GHSA-w3v8-gmh9-3wv7.",
      "id": "BREW-safety-CVE-2026-12876",
      "modified": "2026-09-17T17:35:56Z",
      "published": "2026-09-03T10:05:22Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/security/advisories/GHSA-ff5c-cp5c-9wjf"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/pull/3649"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/commit/43aaca1b9024138421c97f970bf13ee19ac8129d"
        },
        {
          "type": "PACKAGE",
          "url": "https://github.com/nltk/nltk"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/releases/tag/v3.10.3"
        }
      ],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
          "type": "CVSS_V4"
        }
      ],
      "summary": "NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars",
      "upstream": [
        "GHSA-ff5c-cp5c-9wjf",
        "CVE-2026-12876",
        "PYSEC-2026-3869"
      ]
    }

    GHSA-FF5C-CP5C-9WJF

    Vulnerability from github – Published: 2026-09-02 14:33 – Updated: 2026-09-02 14:33
    VLAI
    Summary
    NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
    Details

    nltk.parse.RecursiveDescentParser (and SteppingRecursiveDescentParser) enumerate parses top-down with no bound on the number of recursive steps. A small, crafted context-free grammar makes a short input consume unbounded CPU (and/or exhaust the Python recursion stack), pinning a process indefinitely — a denial of service.

    Proof of concept

    Both of the following hang on a 24-token input (killed after 8s; growth is super-linear in input length), on NLTK develop:

    from nltk import CFG
    from nltk.parse import RecursiveDescentParser
    
    # (a) left recursion -> unbounded recursion
    g = CFG.fromstring("S -> S S | 'a'")
    list(RecursiveDescentParser(g).parse(["a"] * 24))   # hangs
    
    # (b) ambiguous grammar -> exponential number of parses
    g = CFG.fromstring("S -> 'a' S | 'a' S S | 'a'")
    list(RecursiveDescentParser(g).parse(["a"] * 24))   # hangs
    

    Impact

    An application that runs RecursiveDescentParser on a grammar (or an input) drawn from an untrusted source can be driven into an unbounded CPU / stack-exhaustion loop by a tiny payload. No confidentiality or integrity impact; single-process availability only.

    Sibling

    The RegexpTokenizer ReDoS reported alongside this (CVE-2026-12875) is a different class (caller-supplied regex) and is addressed under GHSA-w3v8-gmh9-3wv7.

    Show details on source website

    {
      "affected": [
        {
          "database_specific": {
            "last_known_affected_version_range": "\u003c= 3.10.2"
          },
          "package": {
            "ecosystem": "PyPI",
            "name": "nltk"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.10.3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "aliases": [
        "CVE-2026-12876"
      ],
      "database_specific": {
        "cwe_ids": [
          "CWE-407",
          "CWE-674"
        ],
        "github_reviewed": true,
        "github_reviewed_at": "2026-09-02T14:33:38Z",
        "nvd_published_at": null,
        "severity": "MODERATE"
      },
      "details": "`nltk.parse.RecursiveDescentParser` (and `SteppingRecursiveDescentParser`) enumerate parses top-down with no bound on the number of recursive steps. A small, crafted context-free grammar makes a short input consume unbounded CPU (and/or exhaust the Python recursion stack), pinning a process indefinitely \u2014 a denial of service.\n\n## Proof of concept\n\nBoth of the following hang on a 24-token input (killed after 8s; growth is super-linear in input length), on NLTK develop:\n\n```python\nfrom nltk import CFG\nfrom nltk.parse import RecursiveDescentParser\n\n# (a) left recursion -\u003e unbounded recursion\ng = CFG.fromstring(\"S -\u003e S S | \u0027a\u0027\")\nlist(RecursiveDescentParser(g).parse([\"a\"] * 24))   # hangs\n\n# (b) ambiguous grammar -\u003e exponential number of parses\ng = CFG.fromstring(\"S -\u003e \u0027a\u0027 S | \u0027a\u0027 S S | \u0027a\u0027\")\nlist(RecursiveDescentParser(g).parse([\"a\"] * 24))   # hangs\n```\n\n## Impact\n\nAn application that runs `RecursiveDescentParser` on a grammar (or an input) drawn from an untrusted source can be driven into an unbounded CPU / stack-exhaustion loop by a tiny payload. No confidentiality or integrity impact; single-process availability only.\n\n## Sibling\n\nThe RegexpTokenizer ReDoS reported alongside this (CVE-2026-12875) is a different class (caller-supplied regex) and is addressed under GHSA-w3v8-gmh9-3wv7.",
      "id": "GHSA-ff5c-cp5c-9wjf",
      "modified": "2026-09-02T14:33:39Z",
      "published": "2026-09-02T14:33:38Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/security/advisories/GHSA-ff5c-cp5c-9wjf"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/pull/3649"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/commit/43aaca1b9024138421c97f970bf13ee19ac8129d"
        },
        {
          "type": "PACKAGE",
          "url": "https://github.com/nltk/nltk"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/releases/tag/v3.10.3"
        }
      ],
      "schema_version": "1.4.0",
      "severity": [
        {
          "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
          "type": "CVSS_V4"
        }
      ],
      "summary": "NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars"
    }

    PYSEC-2026-3869

    Vulnerability from pysec - Published: 2026-09-10 09:44 - Updated: 2026-09-10 11:02
    VLAI
    Details

    nltk.parse.RecursiveDescentParser (and SteppingRecursiveDescentParser) enumerate parses top-down with no bound on the number of recursive steps. A small, crafted context-free grammar makes a short input consume unbounded CPU (and/or exhaust the Python recursion stack), pinning a process indefinitely — a denial of service.

    Proof of concept

    Both of the following hang on a 24-token input (killed after 8s; growth is super-linear in input length), on NLTK develop:

    from nltk import CFG
    from nltk.parse import RecursiveDescentParser
    
    # (a) left recursion -> unbounded recursion
    g = CFG.fromstring("S -> S S | 'a'")
    list(RecursiveDescentParser(g).parse(["a"] * 24))   # hangs
    
    # (b) ambiguous grammar -> exponential number of parses
    g = CFG.fromstring("S -> 'a' S | 'a' S S | 'a'")
    list(RecursiveDescentParser(g).parse(["a"] * 24))   # hangs
    

    Impact

    An application that runs RecursiveDescentParser on a grammar (or an input) drawn from an untrusted source can be driven into an unbounded CPU / stack-exhaustion loop by a tiny payload. No confidentiality or integrity impact; single-process availability only.

    Sibling

    The RegexpTokenizer ReDoS reported alongside this (CVE-2026-12875) is a different class (caller-supplied regex) and is addressed under GHSA-w3v8-gmh9-3wv7.

    Impacted products
    Name purl
    nltk pkg:pypi/nltk

    {
      "affected": [
        {
          "package": {
            "ecosystem": "PyPI",
            "name": "nltk",
            "purl": "pkg:pypi/nltk"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.10.3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.8",
            "0.9",
            "0.9.3",
            "0.9.4",
            "0.9.5",
            "0.9.6",
            "0.9.7",
            "0.9.8",
            "0.9.9",
            "2.0.1",
            "2.0.1rc1",
            "2.0.1rc2-git",
            "2.0.1rc3",
            "2.0.1rc4",
            "2.0.2",
            "2.0.3",
            "2.0.4",
            "2.0.5",
            "2.0b4",
            "2.0b5",
            "2.0b6",
            "2.0b7",
            "2.0b8",
            "2.0b9",
            "3.0.0",
            "3.0.0b1",
            "3.0.0b2",
            "3.0.1",
            "3.0.2",
            "3.0.3",
            "3.0.4",
            "3.0.5",
            "3.1",
            "3.10.0",
            "3.10.1",
            "3.10.2",
            "3.2",
            "3.2.1",
            "3.2.2",
            "3.2.3",
            "3.2.4",
            "3.2.5",
            "3.3",
            "3.4",
            "3.4.1",
            "3.4.2",
            "3.4.3",
            "3.4.4",
            "3.4.5",
            "3.5",
            "3.5b1",
            "3.6",
            "3.6.1",
            "3.6.2",
            "3.6.3",
            "3.6.4",
            "3.6.5",
            "3.6.6",
            "3.6.7",
            "3.7",
            "3.8",
            "3.8.1",
            "3.9",
            "3.9.1",
            "3.9.2",
            "3.9.3",
            "3.9.4",
            "3.9b1"
          ]
        }
      ],
      "aliases": [
        "CVE-2026-12876",
        "GHSA-ff5c-cp5c-9wjf"
      ],
      "details": "`nltk.parse.RecursiveDescentParser` (and `SteppingRecursiveDescentParser`) enumerate parses top-down with no bound on the number of recursive steps. A small, crafted context-free grammar makes a short input consume unbounded CPU (and/or exhaust the Python recursion stack), pinning a process indefinitely \u2014 a denial of service.\n\n## Proof of concept\n\nBoth of the following hang on a 24-token input (killed after 8s; growth is super-linear in input length), on NLTK develop:\n\n```python\nfrom nltk import CFG\nfrom nltk.parse import RecursiveDescentParser\n\n# (a) left recursion -\u003e unbounded recursion\ng = CFG.fromstring(\"S -\u003e S S | \u0027a\u0027\")\nlist(RecursiveDescentParser(g).parse([\"a\"] * 24))   # hangs\n\n# (b) ambiguous grammar -\u003e exponential number of parses\ng = CFG.fromstring(\"S -\u003e \u0027a\u0027 S | \u0027a\u0027 S S | \u0027a\u0027\")\nlist(RecursiveDescentParser(g).parse([\"a\"] * 24))   # hangs\n```\n\n## Impact\n\nAn application that runs `RecursiveDescentParser` on a grammar (or an input) drawn from an untrusted source can be driven into an unbounded CPU / stack-exhaustion loop by a tiny payload. No confidentiality or integrity impact; single-process availability only.\n\n## Sibling\n\nThe RegexpTokenizer ReDoS reported alongside this (CVE-2026-12875) is a different class (caller-supplied regex) and is addressed under GHSA-w3v8-gmh9-3wv7.",
      "id": "PYSEC-2026-3869",
      "modified": "2026-09-10T11:02:15.848558Z",
      "published": "2026-09-10T09:44:59.291918Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/security/advisories/GHSA-ff5c-cp5c-9wjf"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/pull/3649"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/commit/43aaca1b9024138421c97f970bf13ee19ac8129d"
        },
        {
          "type": "PACKAGE",
          "url": "https://github.com/nltk/nltk"
        },
        {
          "type": "WEB",
          "url": "https://github.com/nltk/nltk/releases/tag/v3.10.3"
        },
        {
          "type": "PACKAGE",
          "url": "https://pypi.org/project/nltk"
        },
        {
          "type": "ADVISORY",
          "url": "https://github.com/advisories/GHSA-ff5c-cp5c-9wjf"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12876"
        }
      ],
      "severity": [
        {
          "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
          "type": "CVSS_V4"
        }
      ],
      "summary": "NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars"
    }

    UBUNTU-CVE-2026-12876 (CVE-2026-12876)

    Vulnerability from osv_ubuntu – Published: 2026-08-14 00:00 – Updated: 2026-08-14 00:00 – Source website
    VLAI

    {
      "affected": [
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "python-nltk",
                "binary_version": "2.0~b9-0ubuntu4.1~esm6"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:14.04:LTS",
            "name": "nltk",
            "purl": "pkg:deb/ubuntu/nltk@2.0~b9-0ubuntu4.1~esm6?arch=source\u0026distro=esm-infra-legacy/trusty"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.0~b9-0ubuntu4",
            "2.0~b9-0ubuntu4.1~esm2",
            "2.0~b9-0ubuntu4.1~esm4",
            "2.0~b9-0ubuntu4.1~esm5",
            "2.0~b9-0ubuntu4.1~esm6"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "python-nltk",
                "binary_version": "3.1-1ubuntu0.1+esm4"
              },
              {
                "binary_name": "python3-nltk",
                "binary_version": "3.1-1ubuntu0.1+esm4"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:16.04:LTS",
            "name": "nltk",
            "purl": "pkg:deb/ubuntu/nltk@3.1-1ubuntu0.1+esm4?arch=source\u0026distro=esm-apps-legacy/xenial"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.0.4-1",
            "3.0.5-1",
            "3.1-1",
            "3.1-1ubuntu0.1",
            "3.1-1ubuntu0.1+esm1",
            "3.1-1ubuntu0.1+esm2",
            "3.1-1ubuntu0.1+esm3",
            "3.1-1ubuntu0.1+esm4"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "python-nltk",
                "binary_version": "3.2.5-1ubuntu0.1+esm4"
              },
              {
                "binary_name": "python3-nltk",
                "binary_version": "3.2.5-1ubuntu0.1+esm4"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:18.04:LTS",
            "name": "nltk",
            "purl": "pkg:deb/ubuntu/nltk@3.2.5-1ubuntu0.1+esm4?arch=source\u0026distro=esm-apps/bionic"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.2.4-1",
            "3.2.5-1",
            "3.2.5-1ubuntu0.1",
            "3.2.5-1ubuntu0.1+esm1",
            "3.2.5-1ubuntu0.1+esm2",
            "3.2.5-1ubuntu0.1+esm3",
            "3.2.5-1ubuntu0.1+esm4"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "python3-nltk",
                "binary_version": "3.4.5-2ubuntu0.1~esm4"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:20.04:LTS",
            "name": "nltk",
            "purl": "pkg:deb/ubuntu/nltk@3.4.5-2ubuntu0.1~esm4?arch=source\u0026distro=esm-apps/focal"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.4.5-1",
            "3.4.5-2",
            "3.4.5-2ubuntu0.1~esm1",
            "3.4.5-2ubuntu0.1~esm2",
            "3.4.5-2ubuntu0.1~esm3",
            "3.4.5-2ubuntu0.1~esm4"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "python3-nltk",
                "binary_version": "3.7-1ubuntu0.1~esm2"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:22.04:LTS",
            "name": "nltk",
            "purl": "pkg:deb/ubuntu/nltk@3.7-1ubuntu0.1~esm2?arch=source\u0026distro=esm-apps/jammy"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.5-1",
            "3.6.5-1",
            "3.6.7-1",
            "3.7-1",
            "3.7-1ubuntu0.1~esm1",
            "3.7-1ubuntu0.1~esm2"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "python3-nltk",
                "binary_version": "3.8.1-1ubuntu0.1~esm2"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:24.04:LTS",
            "name": "nltk",
            "purl": "pkg:deb/ubuntu/nltk@3.8.1-1ubuntu0.1~esm2?arch=source\u0026distro=esm-apps/noble"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.8.1-1",
            "3.8.1-1ubuntu0.1~esm1",
            "3.8.1-1ubuntu0.1~esm2"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "python3-nltk",
                "binary_version": "3.9.2-1ubuntu0.1~esm2"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:26.04:LTS",
            "name": "nltk",
            "purl": "pkg:deb/ubuntu/nltk@3.9.2-1ubuntu0.1~esm2?arch=source\u0026distro=esm-apps/resolute"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.9.1-2",
            "3.9.1-2build1",
            "3.9.2-1",
            "3.9.2-1ubuntu0.1~esm1",
            "3.9.2-1ubuntu0.1~esm2"
          ]
        }
      ],
      "aliases": [],
      "details": "[Unknown description]",
      "id": "UBUNTU-CVE-2026-12876",
      "modified": "2026-08-14T00:00:00Z",
      "published": "2026-08-14T00:00:00Z",
      "references": [
        {
          "type": "REPORT",
          "url": "https://ubuntu.com/security/CVE-2026-12876"
        },
        {
          "type": "REPORT",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12876"
        },
        {
          "type": "REPORT",
          "url": "https://github.com/nltk/nltk/security/advisories/GHSA-ff5c-cp5c-9wjf"
        }
      ],
      "related": [],
      "schema_version": "1.7.0",
      "severity": [
        {
          "score": "medium",
          "type": "Ubuntu"
        }
      ],
      "upstream": [
        "CVE-2026-12876"
      ]
    }