Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33231

28
FAUCET Score

CVE-2026-33231 is a Denial of Service vulnerability affecting NLTK (Natural Language Toolkit) versions 3.9.3 and prior, where the nltk.app.wordnet_app component allows an unauthenticated remote attacker to shut down the local WordNet Browser HTTP server. Rated High with a CVSS score of 7.5, this vulnerability can be exploited with low attack complexity over the network without authentication, leading to immediate process termination and a complete denial of service. There is no evidence of active exploitation, nor are there publicly available exploit modules or listings in CISA's KEV catalog. Community discussion is minimal, with only one mention observed, indicating low public awareness or interest at this time. The issue has been patched in later versions.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.9.3CPE matchmatch criteria
cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.88%
Probability of exploitation in next 30 days
EPSS Percentile
55.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0088 is in the 30th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: nltkFixed in: 3.9.4
ubuntupatch availablevia ubuntu_usn
Product: nltk (bionic)Fixed in: 3.2.5-1ubuntu0.1+esm4
ubuntupatch availablevia ubuntu_usn
Product: nltk (jammy)Fixed in: 3.7-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: nltk (noble)Fixed in: 3.8.1-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: nltk (resolute)Fixed in: 3.9.2-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: nltk (trusty)Fixed in: 2.0~b9-0ubuntu4.1~esm6
ubuntupatch availablevia ubuntu_usn
Product: nltk (xenial)Fixed in: 3.1-1ubuntu0.1+esm4
ubuntupatch availablevia ubuntu_usn
Product: nltk (focal)Fixed in: 3.4.5-2ubuntu0.1~esm4
golangvendor investigatingvia llm_extracted
hikvisionvendor investigatingvia llm_extracted

Vendor Advisories (4)

ubuntuUSN-8302-1

NLTK vulnerabilities

May 25, 2026
hikvisionllm-hikvision-714727864ede3253HIGH

Unauthenticated remote shutdown in nltk.app.wordnet_app

Mar 19, 2026
pipGHSA-jm6w-m3j8-898ghigh

Unauthenticated remote shutdown in nltk.app.wordnet_app

Mar 19, 2026
golangllm-golang-159e970800ca7895HIGH

Unauthenticated remote shutdown in nltk.app.wordnet_app

Mar 19, 2026

References

access.redhat.com / errata/RHSA-2026:19712
access.redhat.com / errata/RHSA-2026:24977
access.redhat.com / errata/RHSA-2026:37275
access.redhat.com / security/cve/CVE-2026-33231
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-33231.json
github.com / nltk/nltk/commit/bbaae83db86a0f49e00f5b0db44a7254c268de9b
Patch
github.com / nltk/nltk/security/advisories/GHSA-jm6w-m3j8-898g
ExploitVendor Advisory