THREAT OPS › Threat News › [GHSA] GHSA-w3v8-gmh9-3wv7 (high) — NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
[GHSA] GHSA-w3v8-gmh9-3wv7 (high) — NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
GHSA-w3v8-gmh9-3wv7 Severity: high CVE: CVE-2026-80206
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
### Summary The NLTK `tgrep` module accepts user-supplied regular expressions and passes them to the Python `re` engine without a timeout or validation, enabling catastrophic backtracking (ReDoS). Applications that expose the `tgrep` API to external input are vulnera
Indicators of compromise
- CVE-2026-80206cve
- https://www.offgridsec.comurl
Original source: https://github.com/advisories/GHSA-w3v8-gmh9-3wv7