nltk is contains an Inefficient Regular Expression and is vulnerable to regular expression denial of service attacks.
References
https://nvd.nist.gov/vuln/detail/CVE-2021-3828
https://github.com/nltk/nltk/pull/2816
https://github.com/nltk/nltk/commit/…