PyPI package
nltk
pkg:pypi/nltk
Vulnerabilities (23)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-43854 | Hig | 7.5 | < 3.6.6 | 3.6.6 | Dec 23, 2021 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Versions prior to 3.6.5 are vulnerable to regular expression denial of service (ReDoS) attacks. The vulnerability | |
| CVE-2021-3828 | Hig | 7.5 | < 3.6.4 | 3.6.4 | Sep 27, 2021 | nltk is vulnerable to Inefficient Regular Expression Complexity | |
| CVE-2019-14751 | Hig | 7.5 | < 3.4.5 | 3.4.5 | Aug 22, 2019 | NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction. |
- affected < 3.6.6fixed 3.6.6
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Versions prior to 3.6.5 are vulnerable to regular expression denial of service (ReDoS) attacks. The vulnerability
- affected < 3.6.4fixed 3.6.4
nltk is vulnerable to Inefficient Regular Expression Complexity
- affected < 3.4.5fixed 3.4.5
NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.
Page 2 of 2