CVE-2026-81722

Source
https://cve.org/CVERecord?id=CVE-2026-81722
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81722.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-81722
Aliases
  • GHSA-ww6m-cw3f-q94g
Downstream
Published
2026-08-27T14:51:15.857Z
Modified
2026-08-29T03:30:32.747983832Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
nltk PorterStemmer before 3.10.3 Quadratic-time DoS
Details

nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The isconsonant() helper walks backward over the entire run of trailing 'y' characters on every call, and _measure() invokes it for each stem position, causing O(n^2) behavior. A single ~20-50 KB untrusted token consisting of a long run of the letter 'y' followed by a matching suffix (e.g., 'ness') can pin a CPU core for seconds to minutes, causing availability impact.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81722.json",
    "cwe_ids": [
        "CWE-407"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/nltk/nltk

Affected ranges

Type
GIT
Repo
https://github.com/nltk/nltk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.10.3"
        }
    ]
}

Affected versions

2.*
2.0.1rc1
2.0.1rc2
2.0.1rc3
2.0.1rc4
3.*
3.0.0b1
3.0.2
3.0.3
3.0.4
3.0.5
3.0a4
3.1
3.2
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3
3.4
3.4.1
3.4.3
3.4.4
3.5
3.5b1
3.6
3.6.1
3.6.2
3.6.5
3.6.6
3.6.7
3.7
3.8
3.8.1
3.8.2
3.9
3.9.1
3.9.2
3.9.3
3.9.4
v.*
v.3.10.1
v3.*
v3.10.0
v3.10.0-rc1
v3.10.0-rc2
v3.10.1
v3.10.1-rc1
v3.10.1-rc2
v3.10.2
v3.10.2-rc1
v3.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81722.json"