Executive brief
The Natural Language Toolkit (NLTK) is a popular Python library used for processing human language data. A vulnerability in its WordNet Browser component allows an unauthenticated person to remotely shut down the server with a single web request. This can lead to a denial of service, making the tool unavailable for researchers or applications relying on its web interface.
Technical details
The `nltk.app.wordnet_app` component in NLTK versions up to and including 3.9.3 fails to implement authentication for critical server functions. By default, the WordNet Browser HTTP server listens on all interfaces (`0.0.0.0`). An attacker can send a specially crafted HTTP GET request to the `/SHUTDOWN%20THE%20SERVER` endpoint, which triggers an immediate `os._exit(0)` call. This results in a complete process termination and denial of service. The issue is addressed in later versions by binding the server to localhost (`127.0.0.1`) by default and patching the shutdown logic.
Affected products
- nltk nltk <= 3.9.3
- Red Hat Red Hat OpenShift AI 2.25
- Red Hat Red Hat OpenShift AI 3.3
- Red Hat Lightspeed Core
- Red Hat OpenShift Lightspeed
- Red Hat Red Hat Ansible Automation Platform 2
Timeline
- 2026-03-18: advisory: GitHub Security Advisory published
- 2026-03-20: disclosed: CVE published to NVD
- 2026-05-20: patched: Red Hat released security advisory RHSA-2026:19712
References
- https://github.com/nltk/nltk/commit/bbaae83db86a0f49e00f5b0db44a7254c268de9b
- https://github.com/nltk/nltk/security/advisories/GHSA-jm6w-m3j8-898g
- https://access.redhat.com/errata/RHSA-2026:19712
- https://access.redhat.com/errata/RHSA-2026:24977
- https://access.redhat.com/security/cve/CVE-2026-33231
- https://bugzilla.redhat.com/show_bug.cgi?id=2449836
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33231.json