HIGHVulnerability

CVE-2026-78681

NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.

Properties

severity
HIGH
score
7.5
epss_score
0.00294
cve_id
CVE-2026-78681
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-08-25T02:16:52.750
last_modified
2026-09-01T20:09:22.720
epss_percentile
0.2169

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-78681 — Ninja Signal Threat Intelligence | Ninja Signal