CVE-2026-33231

EUVD-2026-13885
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when it is started in its default mode. A simple `GET /SHUTDOWN%20THE%20SERVER` request causes the process to terminate immediately via `os._exit(0)`, resulting in a denial of service. Commit bbaae83db86a0f49e00f5b0db44a7254c268de9b patches the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 55.58%
Affected Products (NVD)
VendorProductVersion
nltknltk
𝑥
≤ 3.9.3
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat OpenShift AI 2.25
1780069222 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1780069226 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1778262893 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1778263054 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782471606 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
nltk
bookworm
no-dsa
bullseye
postponed
forky
3.10.0-1
fixed
sid
3.10.1-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nltk
bionic
Fixed 3.2.5-1ubuntu0.1+esm4
released
focal
Fixed 3.4.5-2ubuntu0.1~esm4
released
jammy
Fixed 3.7-1ubuntu0.1~esm2
released
noble
Fixed 3.8.1-1ubuntu0.1~esm2
released
questing
ignored
resolute
Fixed 3.9.2-1ubuntu0.1~esm2
released
trusty
Fixed 2.0~b9-0ubuntu4.1~esm6
released
xenial
ignored