CVE-2026-33231 is a Denial of Service vulnerability affecting NLTK (Natural Language Toolkit) versions 3.9.3 and prior, where the nltk.app.wordnet_app component allows an unauthenticated remote attacker to shut down the local WordNet Browser HTTP server. Rated High with a CVSS score of 7.5, this vulnerability can be exploited with low attack complexity over the network without authentication, leading to immediate process termination and a complete denial of service. There is no evidence of active exploitation, nor are there publicly available exploit modules or listings in CISA's KEV catalog. Community discussion is minimal, with only one mention observed, indicating low public awareness or interest at this time. The issue has been patched in later versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.9.3CPE matchmatch criteria | cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
NLTK vulnerabilities
May 25, 2026Unauthenticated remote shutdown in nltk.app.wordnet_app
Mar 19, 2026Unauthenticated remote shutdown in nltk.app.wordnet_app
Mar 19, 2026Unauthenticated remote shutdown in nltk.app.wordnet_app
Mar 19, 2026