PatchSiren cyber security CVE debrief
CVE-2026-33231 nltk CVE debrief
CVE-2026-33231 is a high-severity vulnerability in the Natural Language Toolkit (NLTK) that allows unauthenticated remote shutdown of the local WordNet Browser HTTP server. The vulnerability affects NLTK versions 3.9.3 and prior. A simple GET request can cause the process to terminate immediately, resulting in a denial of service. The issue was patched in commit bbaae83db86a0f49e00f5b0db44a7254c268de9b.
- Vendor
- nltk
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-20
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-03-20
- Advisory updated
- 2026-09-09
Who should care
Defenders and administrators of NLTK installations, especially in environments where the WordNet Browser HTTP server is accessible, should verify exposure and assess potential impact.
Why it matters
CVE-2026-33231 is a high-severity vulnerability in NLTK that allows unauthenticated remote shutdown of the local WordNet Browser HTTP server, potentially disrupting natural language processing services. Defenders should verify exposure, assess impact, and apply the patch or mitigations as needed.
- Denial of service via unauthenticated remote shutdown
- Potential disruption of natural language processing services
- Need for verification of NLTK installation exposure
- Priority for applying patch or mitigations
Technical summary
The vulnerability affects NLTK versions 3.9.3 and prior. A simple GET request can cause the process to terminate immediately, resulting in a denial of service. The issue was patched in commit bbaae83db86a0f49e00f5b0db44a7254c268de9b. Defenders should prioritize verifying exposure of NLTK installations and assess potential impact. The vulnerability allows unauthenticated remote shutdown of the local WordNet Browser HTTP server, potentially disrupting natural language processing services. Affected product deployments should be confirmed in managed environments.
Defensive priority
Defenders should prioritize verifying exposure of NLTK installations, especially in environments where the WordNet Browser HTTP server is accessible. They should also assess the potential impact of a denial-of-service attack and apply the patch or mitigations as needed.
Recommended defensive actions
- Verify exposure of NLTK installations
- Assess potential impact of denial-of-service attack
- Apply patch or mitigations
- Monitor for suspicious activity
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The vulnerability is described in the CVE record and NVD vulnerability detail page. The patch is available in the NLTK repository. Evidence is limited; defenders should verify NLTK installation exposure, assess potential impact, and apply patch or mitigations as needed with explicit evidence limits. Limited source detail is available; further verification tasks are required.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-33231 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-33231
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-33231 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-33231
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/nltk/nltk/commit/bbaae83db86a0f49e00f5b0db44a7254c268de9b
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/nltk/nltk/security/advisories/GHSA-jm6w-m3j8-898g
[email protected] - Exploit, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:19712
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:24977
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:37275
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:65126
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-33231
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33231.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.