
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33231 is an unauthenticated remote denial-of-service vulnerability in the NLTK (Natural Language Toolkit) WordNet Browser HTTP server (nltk.app.wordnet_app). Any network-reachable client can terminate the service by sending a single unauthenticated HTTP GET request to a specific endpoint, causing the process to exit immediately via os._exit(0). It affects NLTK versions 3.9.3 and earlier; the patched version is 3.9.4. The vulnerability was published on March 18, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Github Advisory, Red Hat Bugzilla).
The root cause is CWE-306 (Missing Authentication for Critical Function): the WordNet Browser HTTP server exposes a /SHUTDOWN THE SERVER route without any authentication or CSRF protection. In the default operating mode (runBrowser=True, which sets server_mode=False), the request handler in nltk/app/wordnet_app.py checks if the URL-decoded path equals "SHUTDOWN THE SERVER" and, if so, calls os._exit(0) directly, bypassing any graceful shutdown logic. Critically, the server binds to all network interfaces ("", i.e., 0.0.0.0) by default, making it reachable from any host with network access to the listening port. The fix (commit bbaae83) restricts the server binding to 127.0.0.1 (localhost only) (Github Advisory, Patch Commit).
Successful exploitation results in an immediate, complete loss of availability of the NLTK WordNet Browser service — the process terminates with exit code 0 and does not restart automatically. There is no impact on confidentiality or data integrity, and no lateral movement potential is associated with this vulnerability. The risk is primarily relevant to users or organizations that expose the WordNet Browser port to untrusted networks, such as in containerized or shared research environments (Github Advisory).
A public proof-of-concept exploit is available in the official GitHub Security Advisory, consisting of concrete curl and Docker commands that reproduce the denial-of-service condition with a single HTTP GET request. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.041% (0.02% per GitHub Advisory), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Feedly).
nltk.app.wordnet_app (WordNet Browser) with an exposed HTTP port (default: 8000 or custom, e.g., 8004) using network scanners such as Nmap or Shodan, targeting NLTK versions ≤ 3.9.3.curl -s -o /tmp/wn_before.html -w '%{http_code}\n' 'http://<target>:<port>/'Expected result: HTTP 200.curl -s -o /tmp/wn_shutdown.html -w '%{http_code}\n' 'http://<target>:<port>/SHUTDOWN%20THE%20SERVER'The server processes the URL-decoded path "SHUTDOWN THE SERVER", matches the handler condition, and calls os._exit(0), terminating the process immediately.curl -s -o /tmp/wn_after.html -w '%{http_code}\n' 'http://<target>:<port>/'Expected result: connection refused (HTTP 000) (Github Advisory)./SHUTDOWN%20THE%20SERVER or URL-decoded equivalent SHUTDOWN THE SERVER; sudden loss of connectivity to the WordNet Browser service port.GET /SHUTDOWN%20THE%20SERVER from an unexpected or external source IP; log message "Server shutting down!" in the application or container logs immediately before service termination.nltk.app.wordnet_app with exit code 0; container status changing to Exited (0) without a deliberate shutdown action (Github Advisory).Upgrade NLTK to version 3.9.4 or later, which patches the issue by binding the WordNet Browser HTTP server to 127.0.0.1 (localhost only) instead of all interfaces, preventing remote access to the shutdown endpoint (Github Advisory, Patch Commit). As an interim workaround, implement firewall rules or network segmentation to restrict access to the WordNet Browser port to trusted clients only, and avoid exposing the service on public or untrusted network interfaces. IBM has also released patches for affected products including IBM API Connect and IBM watsonx Orchestrate Developer Edition (IBM Advisory, IBM watsonx Advisory).
The vulnerability was reported by security researcher leduckhuong and analyzed by v-kondratenko, with the advisory published by NLTK maintainer alvations on March 18, 2026 (Github Advisory). Red Hat tracked the issue via Bugzilla with a high severity rating, and OpenSUSE issued a security announcement for affected packages (Red Hat Bugzilla). Social media mentions were observed on Bluesky and Mastodon, and the vulnerability was covered in Linux security news outlets including linuxsecurity.com and pro-linux.de.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
nltk: 3.2.5-1ubuntu0.1+esm4
devel
nltk
focal (esm-apps)
nltk: 3.4.5-2ubuntu0.1~esm4
jammy
nltk
jammy (esm-apps)
nltk: 3.7-1ubuntu0.1~esm2
noble
nltk
noble (esm-apps)
nltk: 3.8.1-1ubuntu0.1~esm2
resolute
nltk
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."