CVE-2026-81727
- EPSS 0.14%
- Veröffentlicht 27.08.2026 14:51:19
- Zuletzt bearbeitet 31.08.2026 19:08:45
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attack...
CVE-2026-81726
- EPSS 0.27%
- Veröffentlicht 27.08.2026 14:51:18
- Zuletzt bearbeitet 31.08.2026 19:06:49
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through Transi...
CVE-2026-81725
- EPSS 0.22%
- Veröffentlicht 27.08.2026 14:51:18
- Zuletzt bearbeitet 01.09.2026 20:06:33
NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit ...
CVE-2026-81724
- EPSS 0.26%
- Veröffentlicht 27.08.2026 14:51:17
- Zuletzt bearbeitet 31.08.2026 19:06:33
NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial...
CVE-2026-81723
- EPSS 0.22%
- Veröffentlicht 27.08.2026 14:51:16
- Zuletzt bearbeitet 24.09.2026 20:44:42
NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to cause severe CPU ...
CVE-2026-81722
- EPSS 0.34%
- Veröffentlicht 27.08.2026 14:51:15
- Zuletzt bearbeitet 31.08.2026 15:44:19
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' characters on every cal...
CVE-2026-80206
- EPSS 0.25%
- Veröffentlicht 26.08.2026 10:28:15
- Zuletzt bearbeitet 01.09.2026 20:07:46
NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search...
CVE-2026-80205
- EPSS 0.38%
- Veröffentlicht 26.08.2026 10:28:14
- Zuletzt bearbeitet 03.09.2026 05:15:15
NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers can supply crafted r...
CVE-2026-79676
- EPSS 0.3%
- Veröffentlicht 25.08.2026 15:16:01
- Zuletzt bearbeitet 31.08.2026 19:06:13
NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus ...
CVE-2026-79675
- EPSS 0.4%
- Veröffentlicht 25.08.2026 15:16:00
- Zuletzt bearbeitet 01.09.2026 20:08:49
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile t...