VYPR

apk package

wolfi/py3.12-nltk

pkg:apk/wolfi/py3.12-nltk

Vulnerabilities (8)

  • CVE-2026-66393HigAug 22, 2026
    affected < 3.9.4-r0fixed 3.9.4-r0

    NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unh

  • CVE-2026-12243Jun 30, 2026
    affected < 3.10.0-r0fixed 3.10.0-r0

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-54293HigJun 22, 2026
    affected < 3.10.0-r0fixed 3.10.0-r0

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path traversal via URL-encoded path separators and

  • CVE-2026-33236HigMar 20, 2026
    affected < 3.9.4-r0fixed 3.9.4-r0

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the `subdir` and `id` attributes when processi

  • CVE-2026-33231HigMar 20, 2026
    affected < 3.9.4-r0fixed 3.9.4-r0

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet B

  • CVE-2026-33230MedMar 20, 2026
    affected < 3.9.4-r0fixed 3.9.4-r0

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a reflected cross-site scripting issue in the `looku

  • CVE-2025-14009HigFeb 18, 2026
    affected < 3.9.3-r0fixed 3.9.3-r0

    A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This allows attackers to craft malicious zip pack

  • CVE-2024-39705CriJun 27, 2024
    affected < 3.8.2-r0fixed 3.8.2-r0

    NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.