Junglewise Threat Intelligence

NLTK Pl196xCorpusReader quadratic ReDoS on malformed TEI blocks

Severity: low · CVSS 3.1 · Published 2026-08-27

Technologies: NLTK Project Natural Language Toolkit. Vendors: NLTK Project.

Executive brief

NLTK is a popular natural language processing library used to parse and analyze text corpora. A vulnerability in its TEI corpus reader allows attackers to cause severe CPU consumption by supplying malformed corpus files with many unclosed XML-like tags, forcing the parser into repeated scanning and effectively denying service to legitimate parsing operations.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) in the Pl196xCorpusReader component, specifically in the TEICorpusView.read_block method. The root cause is the use of lazy regex patterns (.*?) that rescan untrusted XML-like blocks across whole TEI structures. When an attacker supplies a corpus file with many unmatched opening tags and no corresponding closing tags, each regex matching attempt fails and rescans from the next position, causing quadratic runtime growth. The vulnerability is exploitable through public APIs like words() and tagged_words() without requiring authentication or special privileges. A proof-of-concept demonstrates near four-times runtime growth when doubling the number of malformed tags. Patches are available in NLTK 3.10.3 and later.

Affected products

  • NLTK Project NLTK before 3.10.3

Timeline

  • 2026-08-27: disclosed
  • 2026-08-12: patched: Patched in NLTK 3.10.3 and later
  • 2026-09-02: other: Advisory withdrawn as duplicate of GHSA-8mpw-7fpc-4gqj

References