CVE-2026-80206
NLTK 3.10.3 tgrep module allows ReDoS via unvalidated regex in _tgrep_node_action.
- CVSS 8.2
- 1333
- Input Validation and Sanitization
- Remote
NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search against tree node labels without any validation or timeout. An attacker who controls the tgrep pattern (e.g., via tgrep_positions() or tgrep_compile() exposed to external input) can supply a pattern that triggers catastrophic backtracking, causing indefinite CPU saturation that blocks the Python process.
- CWE
- 1333
- CVSS base score
- 8.2
- Published
- 2026-08-26
- OWASP
- A04 Insecure Design
- Orthogonal defect classification
- Timing/Serialization
- Code defect classification
- Timing Issues
- Category
- Input Validation and Sanitization
- Subcategory
- Insecure Parsing or Deserialization
- Accessibility scope
- Remote
- Impact
- Denial of Service (DoS)
- Affected component
- NLTK
- Fixed by upgrading
- Yes
Solution
Upgrade NLTK to version 3.10.3 or later.
Vulnerable code sample
import re
from nltk.tree import Tree
from nltk.tgrep import tgrep_positions
def find_matching_nodes(tree: Tree, pattern: str):
"""
Search tree nodes whose labels match a user‑supplied regular expression
embedded in a tgrep pattern.
"""
# VULNERABLE: compiles and searches user‑controlled regex without limits
compiled = re.compile(pattern)
matches = []
for node, _ in tgrep_positions(tree, f"/{pattern}/"):
if compiled.search(node.label()):
matches.append(node)
return matchesPatched code sample
import re
import regex
from nltk.tree import Tree
from nltk.tgrep import tgrep_positions
def find_matching_nodes(tree: Tree, pattern: str):
"""
Search tree nodes whose labels match a user‑supplied regular expression
embedded in a tgrep pattern, with a safe timeout.
"""
# FIX: use regex module with a timeout to bound backtracking
compiled = regex.compile(pattern, timeout=0.1)
matches = []
for node, _ in tgrep_positions(tree, f"/{pattern}/"):
if compiled.search(node.label()):
matches.append(node)
return matchesPayload
__VAITP_MODEL_REFUSED__
Cite this entry
@misc{vaitp:cve202680206,
title = {{NLTK 3.10.3 tgrep module allows ReDoS via unvalidated regex in _tgrep_node_action.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-80206},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-80206/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
