Executive brief
A vulnerability in the NLTK library's WordNet Browser application allows unauthorized users to remotely shut down the server. This tool is used for browsing the WordNet lexical database, and an exploit would cause the service to become unavailable to all users. Because the server listens on all network interfaces by default, any remote attacker with network access can trigger this shutdown without needing a password or account.
Technical details
The vulnerability is classified as a missing authentication for a critical function (CWE-306) within the `nltk.app.wordnet_app` component. When the WordNet Browser HTTP server is started in its default configuration, it listens on all network interfaces (0.0.0.0). An attacker can send a specifically crafted unauthenticated GET request to the `/SHUTDOWN%20THE%20SERVER` endpoint. The application processes this request by calling `os._exit(0)`, which immediately terminates the server process. This allows any remote attacker with network reachability to the server's port to perform a Denial of Service (DoS) attack. The issue affects NLTK versions up to and including 3.9.3.
Affected products
- nltk nltk/nltk up to 3.9.3
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory