THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w3v8-gmh9-3wv7 (high) — NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

[GHSA] GHSA-w3v8-gmh9-3wv7 (high) — NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

highgithub_advisoriesPublished 2026-09-08

GHSA-w3v8-gmh9-3wv7 Severity: high CVE: CVE-2026-80206

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

### Summary The NLTK `tgrep` module accepts user-supplied regular expressions and passes them to the Python `re` engine without a timeout or validation, enabling catastrophic backtracking (ReDoS). Applications that expose the `tgrep` API to external input are vulnera

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w3v8-gmh9-3wv7