THREAT OPS › Threat News › [GHSA] GHSA-97qj-x29f-37w7 (high) — NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
[GHSA] GHSA-97qj-x29f-37w7 (high) — NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
GHSA-97qj-x29f-37w7 Severity: high CVE: CVE-2026-78681
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
Several XML parsing sites in NLTK still used `xml.etree.ElementTree` directly, which honours `<!ENTITY>` declarations in a document's internal DTD subset. A crafted document a few hundred bytes long can expand to megabytes in memory (each nesting level multiplie
Indicators of compromise
- CVE-2026-78681cve
Original source: https://github.com/advisories/GHSA-97qj-x29f-37w7