GHSA-rrv8-h7p8-rx55
Dashboard / Vulnerabilities / GHSA-rrv8-h7p8-rx55
GHSA-rrv8-h7p8-rx55
Summary: NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
Details: ### Summary NLTK's `Text.findall()` and `TokenSearcher.findall()` methods accept user-supplied regular expressions and pass them to the Python `re` engine without timeout or validation, enabling catastrophic backtracking (ReDoS). This issue is isolated to the `nltk.text` module and was resolved in a prior commit. ### Affected Code `nltk/text.py` — `TokenSearcher.findall()` (line 255) / `Text.findall()` (line 620) `TokenSearcher.__init__` builds an internal string by wrapping each token in angle brackets. The `findall()` method preprocesses the caller-supplied regexp and runs it directly against this string with no timeout: ```python def findall(self, regexp): # Preprocessing does NOT prevent catastrophic backtracking regexp = re.sub(r"\s", "", regexp) regexp = re.sub(r"<", "(?:<(?:", regexp) regexp = re.sub(r">", ")>)", regexp) regexp = re.sub(r"(?<!\\)\.", "[^>]", regexp) # User-controlled regexp executed with no timeout hits = re.findall(regexp, self._raw) ``` The preprocessing transforms `<` and `>` angle-bracket syntax but does not inspect or reject catastrophically backtracking patterns. ### Proof of Concept ```python import nltk import time # Token of 25 'a' characters produces self._raw = "<aaaaaaaaaaaaaaaaaaaaaaaa!>" # The trailing '!' ensures no match, forcing full backtracking. text = nltk.Text(["a" * 25 + "!"]) # Pattern after transformation: # < → (?:<(?: # > → )>) # Becomes: (?:<(?:((a+)+)b)>) # re.findall runs this against "<aaaaaaaaaaaaaaaaaaaaaaaa!>" — hangs. start = time.time() text.findall(r"<((a+)+)b>") # Never returns ``` ### Impact Applications that expose `Text.findall()` to external input are vulnerable to a denial of service. An unauthenticated attacker can cause indefinite CPU saturation with one request, denying service to all other users of the Python process. ### Remediation This vulnerability was patched in commit `d8e4753`. Users should update to the patched version. ### Credit Tool: Kira by [Offgrid Security](https://www.offgridsec.com)
References: https://github.com/nltk/nltk/security/advisories/GHSA-rrv8-h7p8-rx55, https://nvd.nist.gov/vuln/detail/CVE-2026-80205, https://github.com/nltk/nltk/pull/3674, https://github.com/nltk/nltk/commit/d8e47539317b571ab1422981f5b9653d5eae1249, https://github.com/nltk/nltk, https://github.com/nltk/nltk/releases/tag/v3.10.0, https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3750.yaml, https://www.vulncheck.com/advisories/nltk-before-3.10.0-redos-via-text-findall-unvalidated-regex, http://www.openwall.com/lists/oss-security/2026/09/01/3
Affected packages
Package
Name: nltk
Purl: pkg:pypi/nltk
Affected ranges
Type: ECOSYSTEM
Events:
