LIVE · cybersecurity feed
Live wire
vendor

Nltk

21 CVEs published in the last four months. Exploited flaws first.

Critical3
High17
Medium1
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-796579.8criticalnltkNLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust11d ago
CVE-2026-796759.8criticalnltkNLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() funct11d ago
CVE-2026-786839.6criticalnltkNLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the Tran12d ago
CVE-2026-796748.2highnltkNLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows 11d ago
CVE-2026-332368.1highnltkNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting rese169d ago
CVE-2026-122527.8highnltkIn nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, St64d ago
CVE-2025-714087.8highnltkNLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocat43d ago
CVE-2026-332317.5highnltkNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting rese169d ago
CVE-2026-786817.5highnltkNLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declar12d ago
CVE-2026-786827.5highnltkNLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.12d ago
CVE-2026-623847.5highnltkNLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers t14d ago
CVE-2026-817227.5highnltknltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial o9d ago
CVE-2026-542937.5highnltkNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting rese75d ago
CVE-2026-633127.5highnltkNLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pat14d ago
CVE-2026-663937.5highnltkNLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that all14d ago
CVE-2026-802057.5highnltkNLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and Tok10d ago
CVE-2026-623887.5highnltkNLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to e14d ago
CVE-2026-817277.1highnltkNLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and D9d ago
CVE-2026-633107.1highnltkNLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloade14d ago
CVE-2026-817267highnltkNLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement9d ago
CVE-2026-332306.1mediumnltkNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting rese169d ago

Filter the full tracker by Nltk