nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing y characters on every call, and _measure() invokes it for each stem position, causing O(n^2) behavior. A single ~20-50 KB untrusted token consisting of a long run of the letter y followed by a matching suffix (e.g., ness) can pin a CPU core for seconds to minutes, causing availability impact.
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Nltk | Nltk | * | 3.10.3 (excluding) |
| Red Hat OpenShift AI 3.5 | RedHat | rhoai/odh-ta-lmes-job-rhel9:1788935863 | * |
| Nltk | Ubuntu | upstream | * |