VYPR

Nltk

by Nltk

pypi: nltk

Source repositories

CVEs (52)

  • CVE-2026-80206MedAug 26, 2026
    risk 0.31cvss 5.9epss 0.00

    NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search against tree node labels…

  • CVE-2026-79676MedAug 25, 2026
    risk 0.31cvss 5.9epss 0.00

    NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data…

  • CVE-2026-62385MedAug 22, 2026
    risk 0.31cvss 5.9epss 0.00

    NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu,…

  • CVE-2026-62383MedAug 22, 2026
    risk 0.29cvss 5.5epss 0.00

    nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by…

  • CVE-2026-81724MedAug 27, 2026
    risk 0.27cvss 5.3epss 0.00

    NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested…

  • CVE-2026-63311MedAug 22, 2026
    risk 0.27cvss 5.3epss 0.00

    NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during socket.getaddrinfo() and returns an empty…

  • CVE-2026-12259MedAug 3, 2026
    risk 0.27cvss 5.3epss 0.00

    In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to tamper with the package response body for `info.url`…

  • CVE-2026-12372LowAug 9, 2026
    risk 0.24cvss 3.7epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared…

  • CVE-2026-81725LowAug 27, 2026
    risk 0.17cvss 3.7epss 0.00

    NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit lazy regex patterns in the…

  • CVE-2026-81723LowAug 27, 2026
    risk 0.17cvss 3.7epss 0.00

    NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to cause severe CPU consumption and denial of…

  • CVE-2026-71514LowAug 22, 2026
    risk 0.09cvss 2.5epss 0.00

    NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the builtin open() rather than the…

  • CVE-2026-63310Aug 22, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Page 3 of 3