Sploitus

CVE-2026-12199

No indexed exploits for CVE-2026-12199 yet

A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when started in its default mode. The server listens on all interfaces and processes a specific unauthenticated GET request (`/SHUTDOWN%20THE%20SERVER`) to terminate the process immediately via `os._exit(0)`. This results in a denial of service, impacting service availability. The issue arises due to insufficient authentication and protection mechanisms for critical server functions.

Affected products
Nltk
Fix
Available
CVSS 3.0
7.5 HIGH
EPSS
0.3% (25th percentile)
Weakness
CWE-306
NVD status
Deferred
Published
2026-06-17
CVE-2026-12199 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-12199 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-12199 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.