THREAT OPS › Threat News › [GHSA] GHSA-fg7f-2386-8897 (high) — Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
[GHSA] GHSA-fg7f-2386-8897 (high) — Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
GHSA-fg7f-2386-8897 Severity: high CVE: CVE-2026-12061
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
### Summary `ReviewsCorpusReader` extracts feature annotations of the form *label* followed by a bracketed signed digit (e.g. a label then `[+2]`) from each review line, using the module-level `FEATURES` regex. The feature-label sub-pattern is unbounded — an op
Indicators of compromise
- CVE-2026-12061cve
Original source: https://github.com/advisories/GHSA-fg7f-2386-8897