Unrated severityNVD Advisory· Published Aug 4, 2026
Debian nltk: In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` func…
CVE-2026-12259
Description
In nltk version 3.9.4, the nltk.downloader.Downloader._download_package() function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to tamper with the package response body for info.url through a compromised mirror, malicious proxy, or other source-substitution condition, leading to the installation of attacker-controlled package bytes. The vulnerability can result in malicious corpus or model content being trusted by downstream users or applications.
Affected products
2Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.