Search CVE reports


Toggle filters

1 – 8 of 8 results


CVE-2026-0848

Medium priority
Needs evaluation

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An...

1 affected package

nltk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nltk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-0847

Medium priority
Needs evaluation

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These...

1 affected package

nltk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nltk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-14009

High priority
Needs evaluation

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks....

1 affected package

nltk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nltk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-39705

Medium priority
Ignored

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

1 affected package

nltk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nltk Ignored Ignored Ignored Ignored
Show less packages

CVE-2021-3842

Medium priority

Some fixes available 4 of 7

nltk is vulnerable to Inefficient Regular Expression Complexity

1 affected package

nltk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nltk Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-43854

Medium priority

Some fixes available 4 of 7

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Versions prior to 3.6.5 are vulnerable to regular expression...

1 affected package

nltk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nltk Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-3828

Medium priority

Some fixes available 10 of 12

nltk is vulnerable to Inefficient Regular Expression Complexity

1 affected package

nltk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nltk Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-14751

Medium priority
Fixed

NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.

1 affected package

nltk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nltk Fixed
Show less packages