cbcvebase.
CVE-2026-12199
published 2026-06-17

CVE-2026-12199: Unauthenticated Denial of Service in nltk.app.wordnet_app A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown…

high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
0.33%
24.5th percentile
Unauthenticated Denial of Service in nltk.app.wordnet_app A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when started in its default mode. The server listens on all interfaces and processes a specific unauthenticated GET request (`/SHUTDOWN%20THE%20SERVER`) to terminate the process immediately via `os._exit(0)`. This results in a denial of service, impacting service availability. The issue arises due to insufficient authentication and protection mechanisms for critical server functions.

Affected

12 ranges
VendorProductVersion rangeFixed in
ansible-automation-platform-25lightspeed-chatbot-rhel8
exploit-intelligence-tech-previewvulnerability-analysis-rhel9
nltknltk_nltkunspecified – latest
openshift-lightspeed-tech-previewlightspeed-rag-tool-rhel9
openshift-lightspeedlightspeed-ocp-rag-rhel9
openshift-lightspeedlightspeed-service-api-rhel9
rhoaiodh-llama-stack-core-rhel9
rhoaiodh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9
rhoaiodh-ta-lmes-job-rhel9
rhoaiodh-trustyai-garak-lls-provider-dsp-rhel9
rhoaiodh-trustyai-nemo-guardrails-server-rhel9
rhoaiodh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9

CVSS provenance

cvelistv5v3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.