{"id":"GHSA-8mpw-7fpc-4gqj","summary":"NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks","details":"### Summary\n\n`Pl196xCorpusReader` still parses whole TEI blocks with multiple lazy regexes over attacker-controlled text. A malformed file with many opening tags and no matching closing tags forces repeated rescans and produces quadratic CPU growth in public reader APIs.\n\n### Details\n\n- **Vulnerability type:** Regular-expression denial of service\n- **Affected component:** `nltk.corpus.reader.pl196x.TEICorpusView.read_block` and `Pl196xCorpusReader` public methods\n- **Affected versions:** Published `3.9.4` and current source `v3.10.0-rc2` both reproduced.\n- **Patched versions:** Not yet patched\n- **Root cause:** Lazy `.*?` whole-block regexes rescan untrusted XML-like blocks from each opening-tag position.\n\nThe parser uses regexes for paragraphs, sentences, and word tags across the whole `\u003ctext\u003e` block. When the attacker supplies many unmatched opening tags, each attempt scans toward the end of the block and fails, then restarts from the next opening tag. There is near four-times runtime growth each time the number of malformed `\u003cp\u003e` tags doubled, through normal public calls such as `words()` and `tagged_words()`.\n\n### PoC\n\n**Preconditions**\n- The application parses attacker-influenced PL196X or TEI-like corpus files through public reader APIs.\n\n**Steps**\n1. Create a corpus file with a valid header followed by a `\u003ctext\u003e` block that contains many opening tags and no matching closing tags.\n2. Instantiate `Pl196xCorpusReader` on that corpus.\n3. Call `words()` or `tagged_words()` and measure elapsed time as the malformed tag count doubles.\n4. Observe near quadratic growth instead of near-linear behavior.\n\n**Minimal reproducible excerpt**\n\n```text\nsize=1000 0.014s\nsize=2000 0.057s\nsize=4000 0.231s\nsize=8000 0.927s\n```\n\n### Impact\n\nA consumer that accepts attacker-influenced corpus files can be forced into heavy CPU use and parser-thread stalling before the application concludes the input contains no valid content.\n\n### Remediation\n\nReplace the whole-block lazy-regex parser with a linear parser or bounded tokenizer, and add regression tests that assert near-linear behavior on malformed inputs with many unmatched tags.","aliases":["CVE-2026-81725","PYSEC-2026-3752"],"modified":"2026-09-08T20:45:04.346016767Z","published":"2026-09-08T20:28:46Z","database_specific":{"github_reviewed_at":"2026-09-08T20:28:46Z","nvd_published_at":null,"cwe_ids":["CWE-1333","CWE-400"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/nltk/nltk/security/advisories/GHSA-8mpw-7fpc-4gqj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81725"},{"type":"WEB","url":"https://github.com/nltk/nltk/commit/7808692d451b962711005d954859bb83aabcf8fa"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"},{"type":"WEB","url":"https://github.com/nltk/nltk/releases/tag/v3.10.3"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3752.yaml"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/nltk-before-3.10.3-regular-expression-denial-of-service-via-pl196xcorpusreader"}],"affected":[{"package":{"name":"nltk","ecosystem":"PyPI","purl":"pkg:pypi/nltk"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.3"}]}],"versions":["0.8","0.9","0.9.3","0.9.4","0.9.5","0.9.6","0.9.7","0.9.8","0.9.9","2.0.1","2.0.1rc1","2.0.1rc2-git","2.0.1rc3","2.0.1rc4","2.0.2","2.0.3","2.0.4","2.0.5","2.0b4","2.0b5","2.0b6","2.0b7","2.0b8","2.0b9","3.0.0","3.0.0b1","3.0.0b2","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.1","3.10.0","3.10.1","3.10.2","3.2","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.3","3.4","3.4.1","3.4.2","3.4.3","3.4.4","3.4.5","3.5","3.5b1","3.6","3.6.1","3.6.2","3.6.3","3.6.4","3.6.5","3.6.6","3.6.7","3.7","3.8","3.8.1","3.9","3.9.1","3.9.2","3.9.3","3.9.4","3.9b1"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.10.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-8mpw-7fpc-4gqj/GHSA-8mpw-7fpc-4gqj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}