Junglewise Threat Intelligence

CVE-2026-33231: NLTK unauthenticated remote shutdown in WordNet Browser

CVE-2026-33231 · Severity: high · CVSS 7.5 · Published 2026-03-20

Technologies: Nltk, Red Hat OpenShift Lightspeed, Red Hat Lightspeed Core. Vendors: Red Hat, PyPI.

Executive brief

The Natural Language Toolkit (NLTK) is a popular Python library used for processing human language data. A vulnerability in its WordNet Browser component allows an unauthenticated person to remotely shut down the server with a single web request. This can lead to a denial of service, making the tool unavailable for researchers or applications relying on its web interface.

Technical details

The `nltk.app.wordnet_app` component in NLTK versions up to and including 3.9.3 fails to implement authentication for critical server functions. By default, the WordNet Browser HTTP server listens on all interfaces (`0.0.0.0`). An attacker can send a specially crafted HTTP GET request to the `/SHUTDOWN%20THE%20SERVER` endpoint, which triggers an immediate `os._exit(0)` call. This results in a complete process termination and denial of service. The issue is addressed in later versions by binding the server to localhost (`127.0.0.1`) by default and patching the shutdown logic.

Affected products

  • nltk nltk <= 3.9.3
  • Red Hat Red Hat OpenShift AI 2.25
  • Red Hat Red Hat OpenShift AI 3.3
  • Red Hat Lightspeed Core
  • Red Hat OpenShift Lightspeed
  • Red Hat Red Hat Ansible Automation Platform 2

Timeline

  • 2026-03-18: advisory: GitHub Security Advisory published
  • 2026-03-20: disclosed: CVE published to NVD
  • 2026-05-20: patched: Red Hat released security advisory RHSA-2026:19712

References

Related threats