CVE-2026-79674
- EPSS 0.23%
- Veröffentlicht 25.08.2026 15:16:00
- Zuletzt bearbeitet 31.08.2026 19:06:01
NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and...
CVE-2026-79657
- EPSS 1.17%
- Veröffentlicht 25.08.2026 11:33:22
- Zuletzt bearbeitet 08.10.2026 16:17:44
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namesp...
CVE-2026-78683
- EPSS 0.28%
- Veröffentlicht 25.08.2026 01:30:39
- Zuletzt bearbeitet 31.08.2026 19:05:09
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing ...
CVE-2026-78682
- EPSS 0.25%
- Veröffentlicht 25.08.2026 01:30:38
- Zuletzt bearbeitet 08.10.2026 16:17:44
NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname...
CVE-2026-78681
- EPSS 0.28%
- Veröffentlicht 25.08.2026 01:30:37
- Zuletzt bearbeitet 01.09.2026 20:09:22
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabyte...
CVE-2026-78680
- EPSS 0.12%
- Veröffentlicht 25.08.2026 01:30:37
- Zuletzt bearbeitet 23.09.2026 18:14:58
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary in the search...
CVE-2026-70626
- EPSS 0.14%
- Veröffentlicht 22.08.2026 15:16:21
- Zuletzt bearbeitet 31.08.2026 19:09:01
NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for...
CVE-2026-66393
- EPSS 0.34%
- Veröffentlicht 22.08.2026 15:16:19
- Zuletzt bearbeitet 27.08.2026 14:47:55
NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the rec...
CVE-2026-65915
- EPSS 0.29%
- Veröffentlicht 22.08.2026 15:16:19
- Zuletzt bearbeitet 31.08.2026 18:39:00
NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.lo...
CVE-2026-63312
- EPSS 0.49%
- Veröffentlicht 22.08.2026 15:16:19
- Zuletzt bearbeitet 31.08.2026 18:40:02
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary...