VYPR

nltk

by Debian

Source repositories

CVEs (1)

  • CVE-2026-12259MedAug 3, 2026
    risk 0.00cvss 5.3epss 0.00

    In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to tamper with the package response body for `info.url`…