XML Entity Expansion in Natural Language Toolkit - #VU141418

 

XML Entity Expansion in Natural Language Toolkit - #VU141418

Published: August 11, 2026 / Updated: August 15, 2026


Vulnerability identifier: #VU141418
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-776
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper restriction of recursive entity references in DTDs in xml.etree.ElementTree parsing sites within NLTK when parsing crafted XML documents containing internal entity declarations. A remote attacker can supply a specially crafted XML document to cause a denial of service.

External entities are not resolved, so the issue is limited to memory amplification during XML parsing rather than file disclosure.


Affected software

Natural Language Toolkit

Remediation

Install security update from vendor's website.

Natural Language Toolkit - update to 3.10.3

External References

Related Security Bulletins