CVE-2026-81724: Nltk

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets that exceed Python's recursion limit and raise an unhandled RecursionError, crashing applications that parse user-supplied feature structures or feature grammars.

Affected products

  • Nltk Nltk: before 3.10.3 (fixed in 3.10.3)

Published 2026-08-27. Last modified 2026-08-31.