NLTK 在 3.10.3 版本之前的多个模块中使用 xml.etree.ElementTree 来解析 XML,该解析器会处理文档 DTD 中声明的实体。攻击者可以构造包含嵌套实体声明的 XML 有效载荷,这些实体在内存中从数百字节膨胀至数兆字节,从而导致拒绝服务(DoS)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-79657 | 9.8 CRITICAL | NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization |
| CVE-2026-79675 | 9.8 CRITICAL | NLTK before 3.10.3 JVM Argument Injection via Per-Call Options |
| CVE-2026-78683 | 9.6 CRITICAL | NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization |
| CVE-2026-79674 | 8.2 HIGH | NLTK 3.10.2 Path Traversal via corpus-reader constructors |
| CVE-2026-78680 | 7.8 HIGH | NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary |
| CVE-2026-78682 | 7.5 HIGH | NLTK before 3.10.3 SSRF Protection Bypass via Proxy |
| CVE-2026-79676 | 5.9 MEDIUM | NLTK before 3.10.3 Path Traversal via Symlink Bypass |
No comments yet