NLTKGHSA-rqjh-jp2r-59cj
NLTK Vulnerable to REDoS
High7.5CVE-2021-3842 · Published Jan 6, 2022 · updated Sep 26, 2024
NLTK is vulnerable to REDoS in some RegexpTaggers used in the functions `get_pos_tagger` and `malt_regex_tagger`.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| nltk PyPI | < 3.6.6 | 3.6.6 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-1333
- Also known as
- CVE-2021-3842, PYSEC-2022-5
More NLTK advisories
All NLTK| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 4 | NLTK has a Path Traversal issue | High8.6 | No fix yet |
| Feb 18 | NLTK has a Zip Slip Vulnerability | Critical10.0 | 3.9.3 |
| Jun 282024 | ntlk unsafe deserialization vulnerability | High7.5 | 3.9 |
| Jan 62022 | Inefficient Regular Expression Complexity in nltk (word_tokenize, sent_tokenize) | High7.5 | 3.6.6 |
| Sep 292021 | NLTK Vulnerable to REDoS | High7.5 | 3.6.4 |
| Aug 232019 | NLTK Vulnerable To Path Traversal | High7.5 | 3.4.5 |