THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-97qj-x29f-37w7 (high) — NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

[GHSA] GHSA-97qj-x29f-37w7 (high) — NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

medgithub_advisoriesPublished 2026-09-08

GHSA-97qj-x29f-37w7 Severity: high CVE: CVE-2026-78681

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

Several XML parsing sites in NLTK still used `xml.etree.ElementTree` directly, which honours `<!ENTITY>` declarations in a document's internal DTD subset. A crafted document a few hundred bytes long can expand to megabytes in memory (each nesting level multiplie

Indicators of compromise

Original source: https://github.com/advisories/GHSA-97qj-x29f-37w7