CVE-2026-33231
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, nltk.app.wordnet_app allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when it is started in its default mode. A simple GET /SHUTDOWN%20THE%20SERVER request causes the process to terminate immediately via os._exit(0), resulting in a denial of service.
Commit bbaae83db86a0f49e00f5b0db44a7254c268de9b patches the issue.
HIGH · CVSS 7.5
EPSS 0.0002
Act now
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0