Vulnerability Description
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' characters on every call, and _measure() invokes it for each stem position, causing O(n^2) behavior. A single ~20-50 KB untrusted token consisting of a long run of the letter 'y' followed by a matching suffix (e.g., 'ness') can pin a CPU core for seconds to minutes, causing availability impact.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nltk | Nltk | < 3.10.3 |
Related Weaknesses (CWE)
References
- https://github.com/nltk/nltk/security/advisories/GHSA-ww6m-cw3f-q94gExploitVendor Advisory
- https://www.vulncheck.com/advisories/nltk-porterstemmer-before-3.10.3-quadratic-Third Party Advisory
- https://github.com/nltk/nltk/security/advisories/GHSA-ww6m-cw3f-q94gExploitVendor Advisory
FAQ
What is CVE-2026-81722?
CVE-2026-81722 is a vulnerability with a CVSS score of 7.5 (HIGH). nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the ...
How severe is CVE-2026-81722?
CVE-2026-81722 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-81722?
Check the references section above for vendor advisories and patch information. Affected products include: Nltk Nltk.