{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nltk--3.10.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-72818"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NLTK (\u003c 3.10.1)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["NLTK Project"],"content_html":"\u003cp\u003eThe NLTK library (versions prior to 3.10.1) contains a Regular Expression Denial of Service (ReDoS) vulnerability in the 'nltk/tokenize/casual.py' module. The 'URLS' regular expression, used by 'TweetTokenizer.WORD_RE' and 'casual_tokenize', features an unbounded domain-label repetition pattern '[a-z0-9]+(?:[.-][a-z0-9]+)*'. Because the regex engine attempts to process crafted input strings by exploring all possible partition paths before eventually failing at the missing trailing top-level domain, an attacker can consume significant CPU cycles. A few kilobytes of specially formatted input can stall a single-threaded process for minutes. Since 'TweetTokenizer' is commonly used to process untrusted social-media input, any application exposing this functionality to the internet is susceptible to unauthenticated denial-of-service attacks. The vulnerability is remediated in NLTK version 3.10.1, which introduces bounds to the label repetition.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in significant CPU exhaustion on systems utilizing the NLTK library to parse untrusted text. This impact is primarily observed in web services that provide social-media analysis or processing features. By submitting relatively small, malicious payloads, an attacker can effectively perform a denial-of-service attack, rendering the processing service unavailable or causing cascading latency issues in the application environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the NLTK library to version 3.10.1 or later immediately to patch CVE-2026-72818.\u003c/li\u003e\n\u003cli\u003eAudit application code to identify endpoints that pass user-submitted text directly to 'nltk.tokenize.casual_tokenize' or 'TweetTokenizer.tokenize'.\u003c/li\u003e\n\u003cli\u003eImplement input length validation and timeout mechanisms on all text-processing endpoints to mitigate the impact of potential ReDoS attacks until patching can be completed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T23:26:38Z","date_published":"2026-08-20T23:26:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nltk-redos/","summary":"The NLTK library's TweetTokenizer is vulnerable to a ReDoS attack due to an unbounded regular expression, allowing unauthenticated attackers to trigger CPU exhaustion.","title":"NLTK TweetTokenizer Regular Expression Denial of Service","url":"https://feed.craftedsignal.io/briefs/2026-08-nltk-redos/"}],"language":"en","title":"CraftedSignal Threat Feed - NLTK (\u003c 3.10.1)","version":"https://jsonfeed.org/version/1.1"}