VDB

CVE-2026-33231

CVE-2026-33231 PUBLISHED CVSS 7.5 HIGH

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when it is started in its default mode. A simple `GET /SHUTDOWN%20THE%20SERVER` request causes the process to terminate immediately via `os._exit(0)`, resulting in a denial of service. Commit bbaae83db86a0f49e00f5b0db44a7254c268de9b patches the issue.

EPSS 0.02% · 5.8th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.02%
5.8th percentile

Affected Products

VendorProductVersions
PyPInltk0, 0, 0
nltknltk0, <= 3.9.3, 0

Timeline

  • Mar 19, 2026 CVE Published
  • Mar 20, 2026 Security Advisory
  • Mar 20, 2026 PoC Published
  • Mar 20, 2026 PoC Published
  • Mar 21, 2026 EPSS Score
  • Mar 22, 2026 EPSS Score
  • Mar 22, 2026 Coalition ESS Score
  • Mar 23, 2026 EPSS Score
  • Mar 24, 2026 EPSS Score
  • Mar 24, 2026 PoC Published
  • Mar 25, 2026 EPSS Score
  • May 18, 2026 EPSS Score

References

…and 2 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›