CVE-2026-63311
- EPSS 0.25%
- Veröffentlicht 22.08.2026 15:16:19
- Zuletzt bearbeitet 27.08.2026 19:42:17
NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during socket.getaddr...
CVE-2026-63310
- EPSS 0.11%
- Veröffentlicht 22.08.2026 15:16:19
- Zuletzt bearbeitet 15.09.2026 00:16:57
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-62385
- EPSS 0.29%
- Veröffentlicht 22.08.2026 15:16:18
- Zuletzt bearbeitet 31.08.2026 18:50:08
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can expl...
CVE-2026-62388
- EPSS 0.33%
- Veröffentlicht 22.08.2026 15:16:18
- Zuletzt bearbeitet 27.08.2026 19:54:52
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the...
CVE-2026-62384
- EPSS 0.49%
- Veröffentlicht 22.08.2026 15:16:18
- Zuletzt bearbeitet 02.09.2026 17:52:40
NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the cor...
CVE-2026-62383
- EPSS 0.14%
- Veröffentlicht 22.08.2026 15:16:17
- Zuletzt bearbeitet 27.08.2026 21:43:41
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files acce...
CVE-2026-71514
- EPSS 0.14%
- Veröffentlicht 22.08.2026 14:16:33
- Zuletzt bearbeitet 02.09.2026 17:44:12
NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the built...
CVE-2026-71513
- EPSS 0.78%
- Veröffentlicht 22.08.2026 14:16:33
- Zuletzt bearbeitet 16.09.2026 13:19:34
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the a...
CVE-2026-72818
- EPSS -
- Veröffentlicht 20.08.2026 22:18:05
- Zuletzt bearbeitet 24.09.2026 20:02:50
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting ...
CVE-2026-12372
- EPSS 0.26%
- Veröffentlicht 09.08.2026 22:45:52
- Zuletzt bearbeitet 04.09.2026 13:59:06
A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to rejec...