VYPR

Nltk

by Nltk

pypi: nltk

Source repositories

CVEs (24)

  • CVE-2026-33230MedMar 20, 2026
    risk 0.33cvss 6.1epss 0.00

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a reflected cross-site scripting issue in the…

  • CVE-2026-12261MedAug 7, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of package-isolated roots, and validates package…

  • CVE-2026-12372LowAug 9, 2026
    risk 0.24cvss 3.7epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared…

  • CVE-2026-12259MedAug 3, 2026
    risk 0.00cvss 5.3epss 0.00

    In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to tamper with the package response body for `info.url`…

Page 2 of 2