CVE-2026-33231
In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when it is started in its default mode.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when it is started in its default mode. A simple `GET /SHUTDOWN%20THE%20SERVER` request causes the process to terminate immediately via `os._exit(0)`, resulting in a denial of service. Commit bbaae83db86a0f49e00f5b0db44a7254c268de9b patches the issue.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- nltk/nltk
- Source
- security-advisories@github.com
References
- https://github.com/nltk/nltk/commit/bbaae83db86a0f49e00f5b0db44a7254c268de9bPatch
- https://github.com/nltk/nltk/security/advisories/GHSA-jm6w-m3j8-898gExploit, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:19712
- https://access.redhat.com/errata/RHSA-2026:24977
- https://access.redhat.com/errata/RHSA-2026:37275
- https://access.redhat.com/errata/RHSA-2026:65126
- https://access.redhat.com/security/cve/CVE-2026-33231
- https://bugzilla.redhat.com/show_bug.cgi?id=2449836
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33231.json
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.