VYPR

PyPI package

nltk

pkg:pypi/nltk

Vulnerabilities (23)

  • CVE-2021-43854HigDec 23, 2021
    affected < 3.6.6fixed 3.6.6

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Versions prior to 3.6.5 are vulnerable to regular expression denial of service (ReDoS) attacks. The vulnerability

  • CVE-2021-3828HigSep 27, 2021
    affected < 3.6.4fixed 3.6.4

    nltk is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2019-14751HigAug 22, 2019
    affected < 3.4.5fixed 3.4.5

    NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.

Page 2 of 2