VYPR

PyPI package

nltk

pkg:pypi/nltk

Vulnerabilities (23)

  • CVE-2026-79676MedAug 25, 2026
    affected < 3.10.3fixed 3.10.3

    NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data roo

  • CVE-2026-79674HigAug 25, 2026
    affected < 3.10.3fixed 3.10.3

    NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constr

  • CVE-2026-79657CriAug 25, 2026
    affected < 3.10.3fixed 3.10.3

    NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokeniz

  • CVE-2026-78683CriAug 25, 2026
    affected < 3.10.0fixed 3.10.0

    NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through Warnin

  • CVE-2026-78682HigAug 25, 2026
    affected < 3.10.3fixed 3.10.3

    NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler in

  • CVE-2026-78681HigAug 25, 2026
    affected < 3.10.3fixed 3.10.3

    NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of

  • CVE-2026-63311MedAug 22, 2026
    affected < 3.10.0fixed 3.10.0

    NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during socket.getaddrinfo() and returns an empty li

  • CVE-2026-62388HigAug 22, 2026
    affected < 3.10.0fixed 3.10.0

    NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls th

  • CVE-2026-62385MedAug 22, 2026
    affected < 3.10.0fixed 3.10.0

    NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, an

  • CVE-2026-62384HigAug 22, 2026
    affected >= 3.10.0, < 3.10.2fixed 3.10.2

    NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass t

  • CVE-2026-62383MedAug 22, 2026
    affected >= 3.10.0, < 3.10.2fixed 3.10.2

    nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calli

  • CVE-2026-54293HigJun 22, 2026
    affected <= 3.9.4

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path traversal via URL-encoded path separators and

  • CVE-2026-33236HigMar 20, 2026
    affected <= 3.9.2

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the `subdir` and `id` attributes when processi

  • CVE-2026-33231HigMar 20, 2026
    affected < 3.9.4fixed 3.9.4

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet B

  • CVE-2026-33230MedMar 20, 2026
    affected < 3.9.4fixed 3.9.4

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a reflected cross-site scripting issue in the `looku

  • CVE-2026-0846HigMar 9, 2026
    affected < 3.9.3fixed 3.9.3

    A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensit

  • CVE-2026-0847HigMar 4, 2026
    affected <= 3.9.2

    A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fail to properly sanitize or validate file pa

  • CVE-2025-14009HigFeb 18, 2026
    affected < 3.9.3fixed 3.9.3

    A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This allows attackers to craft malicious zip pack

  • CVE-2024-39705CriJun 27, 2024
    affected < 3.9fixed 3.9

    NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

  • CVE-2021-3842HigJan 4, 2022
    affected < 3.6.6fixed 3.6.6

    nltk is vulnerable to Inefficient Regular Expression Complexity

Page 1 of 2