Skip to content
NLTKGHSA-rqjh-jp2r-59cj

NLTK Vulnerable to REDoS

High7.5CVE-2021-3842 · Published Jan 6, 2022 · updated Sep 26, 2024

NLTK is vulnerable to REDoS in some RegexpTaggers used in the functions `get_pos_tagger` and `malt_regex_tagger`.

GitHub advisory

Affected versions

PackageAffectedFixed in
nltk
PyPI
< 3.6.63.6.6
Details and references

More NLTK advisories

All NLTK
Advisory
NLTK has a Path Traversal issue
High8.6Mar 4
NLTK has a Zip Slip Vulnerability
Critical10.0Feb 18
ntlk unsafe deserialization vulnerability
High7.5Jun 28, 2024
Inefficient Regular Expression Complexity in nltk (word_tokenize, sent_tokenize)
High7.5Jan 6, 2022
NLTK Vulnerable to REDoS
High7.5Sep 29, 2021
NLTK Vulnerable To Path Traversal
High7.5Aug 23, 2019

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.