Natural Language Toolkit是Natural Language Toolkit组织开源的一个自然语言处理工具包。 Natural Language Toolkit 3.10.3之前版本存在服务端请求伪造漏洞,该漏洞源于在配置HTTP代理时,nltk.pathsec.urlopen及调用者nltk.data.load、nltk.downloader.Downloader.index/download对目标主机名验证不足,导致代理可能将请求转发至内部回环服务,攻击者利用此漏洞可泄露内部HT
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: internal loopback resource exfiltrated -- fetched PROOF_0f4375b9e3b5ba5d through attacker proxy (destination 127.0.0.1 never re-validated)
| CVE-2026-79657 | 9.8 CRITICAL | NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization |
| CVE-2026-79675 | 9.8 CRITICAL | NLTK before 3.10.3 JVM Argument Injection via Per-Call Options |
| CVE-2026-78683 | 9.6 CRITICAL | NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization |
| CVE-2026-79674 | 8.2 HIGH | NLTK 3.10.2 Path Traversal via corpus-reader constructors |
| CVE-2026-78680 | 7.8 HIGH | NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary |
| CVE-2026-78681 | 7.5 HIGH | NLTK before 3.10.3 Entity Expansion DoS via ElementTree |
| CVE-2026-79676 | 5.9 MEDIUM | NLTK before 3.10.3 Path Traversal via Symlink Bypass |
No comments yet