Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

nltk — Vulnerabilities & Security Advisories 44

Browse all 44 CVE security advisories affecting nltk. AI-powered Chinese analysis, POCs, and references for each vulnerability.

NLTK is a Python library for natural language processing, widely used in text analysis, machine learning, and computational linguistics applications. Historically, it has been susceptible to remote code execution vulnerabilities through unsafe deserialization of pickled data, cross-site scripting flaws in web-based implementations, and privilege escalation via insecure file operations. While no major public security incidents have been widely documented, the 10 recorded CVEs highlight recurring issues related to input validation and unsafe data handling. Its extensive use in data science pipelines makes it a potential attack vector for compromising systems processing sensitive text data, particularly when untrusted inputs are processed without proper sanitization.

Top products by nltk: nltk nltk/nltk
CVE ID Title CVSS Severity Published
CVE-2026-81727 NLTK before 3.10.3 Hardlink File Overwrite via downloader — nltk CWE-59 7.1 High 2026-08-27
CVE-2026-81726 NLTK through 3.10.3 Path Traversal via Model-Artifact APIs — nltk CWE-73 7.0 High 2026-08-27
CVE-2026-81725 NLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReader — nltk CWE-400 3.7 Low 2026-08-27
CVE-2026-81724 NLTK before 3.10.3 Denial of Service via Uncontrolled Recursion — nltk CWE-674 5.3 Medium 2026-08-27
CVE-2026-81723 NLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusView — nltk CWE-400 3.7 Low 2026-08-27
CVE-2026-81722 nltk PorterStemmer before 3.10.3 Quadratic-time DoS — nltk CWE-407 7.5 High 2026-08-27
CVE-2026-80206 NLTK 3.10.2 Regular Expression Denial of Service via tgrep — nltk CWE-1333 5.9 Medium 2026-08-26
CVE-2026-80205 NLTK before 3.10.0 ReDoS via Text.findall() unvalidated regex — nltk CWE-1333 7.5 High 2026-08-26
CVE-2026-79676 NLTK before 3.10.3 Path Traversal via Symlink Bypass — nltk CWE-22 5.9 Medium 2026-08-25
CVE-2026-79675 NLTK before 3.10.3 JVM Argument Injection via Per-Call Options — nltk CWE-88 9.8 Critical 2026-08-25
CVE-2026-79674 NLTK 3.10.2 Path Traversal via corpus-reader constructors — nltk CWE-73 8.2 High 2026-08-25
CVE-2026-79657 NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization — nltk CWE-502 9.8 Critical 2026-08-25
CVE-2026-78683 NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization — nltk CWE-502 9.6 Critical 2026-08-25
CVE-2026-78682 NLTK before 3.10.3 SSRF Protection Bypass via Proxy — nltk CWE-918 7.5 High 2026-08-25
CVE-2026-78681 NLTK before 3.10.3 Entity Expansion DoS via ElementTree — nltk CWE-776 7.5 High 2026-08-25
CVE-2026-78680 NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary — nltk CWE-426 7.8 High 2026-08-25
CVE-2026-70626 NLTK before 3.9.4 Symlink Escape via CorpusReader — nltk CWE-59 6.2 Medium 2026-08-22
CVE-2026-66393 NLTK before 3.9.4 Denial of Service via JSONTaggedDecoder — nltk CWE-674 7.5 High 2026-08-22
CVE-2026-65915 NLTK before 3.10.0 Arbitrary File Read via FileSystemPathPointer — nltk CWE-284 6.5 Medium 2026-08-22
CVE-2026-63312 NLTK StreamBackedCorpusView Bypasses pathsec.ENFORCE Arbitrary File Read — nltk CWE-22 7.5 High 2026-08-22
CVE-2026-63311 NLTK before 3.10.0 SSRF via DNS Resolution Failure — nltk CWE-918 5.3 Medium 2026-08-22
CVE-2026-62388 NLTK before 3.10.0 Insecure Default Configuration in pathsec.py — nltk CWE-1188 7.5 High 2026-08-22
CVE-2026-62385 NLTK 3.9.4 Path Traversal via FrameNet and NKJP Readers — nltk CWE-73 5.9 Medium 2026-08-22
CVE-2026-62384 NLTK FramenetCorpusReader Symlink Sandbox Bypass before 3.10.2 — nltk CWE-22 7.5 High 2026-08-22
CVE-2026-62383 nltk IPIPANCorpusReader Symlink Arbitrary File Read — nltk CWE-22 5.5 Medium 2026-08-22
CVE-2026-71513 NLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name Bypass — nltk CWE-502 8.8 High 2026-08-22
CVE-2026-71514 NLTK 3.9.4 through 3.10.2 Path Traversal via CrubadanCorpusReader pathsec Bypass — nltk CWE-22 2.5 Low 2026-08-22
CVE-2026-72818 NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Input — nltk CWE-1333 7.5 High 2026-08-20
CVE-2026-12372 Server-Side Request Forgery (SSRF) in nltk/nltk — nltk/nltk CWE-918 - - 2026-08-09
CVE-2026-12261 Improper Access Control in nltk/nltk — nltk/nltk CWE-284 - - 2026-08-07

This page lists every published CVE security advisory associated with nltk. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.