Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

nltk — Vulnerabilities & Security Advisories 44

Browse all 44 CVE security advisories affecting nltk. AI-powered Chinese analysis, POCs, and references for each vulnerability.

NLTK is a Python library for natural language processing, widely used in text analysis, machine learning, and computational linguistics applications. Historically, it has been susceptible to remote code execution vulnerabilities through unsafe deserialization of pickled data, cross-site scripting flaws in web-based implementations, and privilege escalation via insecure file operations. While no major public security incidents have been widely documented, the 10 recorded CVEs highlight recurring issues related to input validation and unsafe data handling. Its extensive use in data science pipelines makes it a potential attack vector for compromising systems processing sensitive text data, particularly when untrusted inputs are processed without proper sanitization.

Top products by nltk: nltk nltk/nltk
CVE ID Title CVSS Severity Published
CVE-2026-12259 Improper Input Validation in nltk/nltk — nltk/nltk CWE-494 - - 2026-08-03
CVE-2026-12252 Untrusted JAR Code Execution in Multiple Stanford Interface Classes in nltk/nltk — nltk/nltk CWE-94 - - 2026-07-04
CVE-2026-54293 NLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read — nltk CWE-22 7.5 High 2026-06-22
CVE-2026-12199 Unauthenticated Denial of Service in nltk.app.wordnet_app — nltk/nltk CWE-306 - - 2026-06-17
CVE-2026-33236 NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite — nltk CWE-22 8.1 High 2026-03-20
CVE-2026-33231 NLTK has unauthenticated remote shutdown in nltk.app.wordnet_app — nltk CWE-306 7.5 High 2026-03-20
CVE-2026-33230 nltk Vulnerable to Cross-site Scripting — nltk CWE-79 6.1 Medium 2026-03-20
CVE-2026-0846 Arbitrary File Read via Absolute Path Input in nltk.util.filestring() — nltk/nltk CWE-36 7.5 - 2026-03-09
CVE-2026-0848 Arbitrary Code Execution in NLTK StanfordSegmenter via Untrusted JAR Loading — nltk/nltk CWE-20 9.8 - 2026-03-05
CVE-2026-0847 Path Traversal in nltk/nltk — nltk/nltk CWE-22 7.5AI High AI 2026-03-04
CVE-2025-14009 Zip Slip Vulnerability in nltk/nltk Leading to Remote Code Execution — nltk/nltk CWE-94 8.8AI High AI 2026-02-18
CVE-2021-3842 Inefficient Regular Expression Complexity in nltk/nltk — nltk/nltk CWE-1333 7.5 - 2022-01-04
CVE-2021-43854 Inefficient Regular Expression Complexity in nltk — nltk CWE-400 7.5 High 2021-12-23
CVE-2021-3828 Inefficient Regular Expression Complexity in nltk/nltk — nltk/nltk CWE-1333 7.5 - 2021-09-27

This page lists every published CVE security advisory associated with nltk. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.