CVE-2026-12261
- EPSS 0.19%
- Veröffentlicht 07.08.2026 06:25:10
- Zuletzt bearbeitet 04.09.2026 14:40:11
A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of package-isolated r...
CVE-2026-12259
- EPSS 0.1%
- Veröffentlicht 03.08.2026 07:09:35
- Zuletzt bearbeitet 31.08.2026 19:35:51
In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to tamper with the package ...
CVE-2025-71408
- EPSS 0.18%
- Veröffentlicht 24.07.2026 21:07:49
- Zuletzt bearbeitet 08.10.2026 16:16:53
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoke...
CVE-2026-12252
- EPSS 0.2%
- Veröffentlicht 04.07.2026 00:58:58
- Zuletzt bearbeitet 08.07.2026 15:01:20
In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These classe...
CVE-2026-54293
- EPSS 0.56%
- Veröffentlicht 22.06.2026 17:25:05
- Zuletzt bearbeitet 09.09.2026 13:20:30
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path traversal via U...
CVE-2026-33236
- EPSS 0.58%
- Veröffentlicht 20.03.2026 22:47:10
- Zuletzt bearbeitet 21.07.2026 12:18:07
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the `subdir` and...
CVE-2026-33231
- EPSS 0.88%
- Veröffentlicht 20.03.2026 22:45:40
- Zuletzt bearbeitet 09.09.2026 13:19:24
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote s...
CVE-2026-33230
- EPSS 0.33%
- Veröffentlicht 20.03.2026 22:43:39
- Zuletzt bearbeitet 23.03.2026 19:14:50
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a reflected cross-site...
CVE-2026-0846
- EPSS 0.43%
- Veröffentlicht 09.03.2026 19:19:09
- Zuletzt bearbeitet 15.07.2026 02:17:57
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabl...
- EPSS 0.81%
- Veröffentlicht 05.03.2026 20:48:05
- Zuletzt bearbeitet 21.04.2026 14:56:46
NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An attacker can supply or rep...