CVE-2026-66393 | NLTK up to 3.9.3 JSON Tagged Decoder JSONTaggedDecoder.decode_obj recursion (Nessus ID 339012)
A vulnerability categorized as problematic has been discovered in NLTK up to 3.9.3. This issue affects the function JSONTaggedDecoder.decode_obj of the component JSON Tagged Decoder. The manipulation results in uncontrolled recursion.
This vulnerability is reported as CVE-2026-66393. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.