nltk
- Total products in the ecosystem
- 2
- Total vulnerabilities (90 days)
- 33
en
Verify to analyze this security profile
As of 09/19/2026, nltk recorded 33 security vulnerabilities in the last 90 days across 2 products, including 23 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, nltk had the most security vulnerabilities in the nltk ecosystem, with 29 vulnerabilities—approximately 87.88% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-81727NLTK before 3.10.3 Hardlink File Overwrite via downloader | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/27/2026 | SeverityMedium |
CVE-2026-81726NLTK through 3.10.3 Path Traversal via Model-Artifact APIs | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/27/2026 | SeverityHigh |
CVE-2026-81725NLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReader | Exploitation statusNot known exploited | FixYes | Affected productnltk | Published08/27/2026 | SeverityMedium |
CVE-2026-81724NLTK before 3.10.3 Denial of Service via Uncontrolled Recursion | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/27/2026 | SeverityMedium |
CVE-2026-81723NLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusView | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/27/2026 | SeverityMedium |
CVE-2026-81722nltk PorterStemmer before 3.10.3 Quadratic-time DoS | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/27/2026 | SeverityHigh |
CVE-2026-80206NLTK 3.10.2 Regular Expression Denial of Service via tgrep | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/26/2026 | SeverityHigh |
CVE-2026-80205NLTK before 3.10.0 ReDoS via Text.findall() unvalidated regex | Exploitation statusNot known exploited | FixYes | Affected productnltk | Published08/26/2026 | SeverityHigh |
CVE-2026-79676NLTK before 3.10.3 Path Traversal via Symlink Bypass | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/25/2026 | SeverityHigh |
CVE-2026-79675NLTK before 3.10.3 JVM Argument Injection via Per-Call Options | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/25/2026 | SeverityCritical |
CVE-2026-79674NLTK 3.10.2 Path Traversal via corpus-reader constructors | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/25/2026 | SeverityHigh |
CVE-2026-79657NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/25/2026 | SeverityCritical |
CVE-2026-78683NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/25/2026 | SeverityCritical |
CVE-2026-78682NLTK before 3.10.3 SSRF Protection Bypass via Proxy | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/25/2026 | SeverityHigh |
CVE-2026-78681NLTK before 3.10.3 Entity Expansion DoS via ElementTree | Exploitation statusNot known exploited | FixYes | Affected productnltk | Published08/25/2026 | SeverityHigh |
CVE-2026-78680NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/25/2026 | SeverityHigh |
CVE-2026-70626NLTK before 3.9.4 Symlink Escape via CorpusReader | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/22/2026 | SeverityHigh |
CVE-2026-66393NLTK before 3.9.4 Denial of Service via JSONTaggedDecoder | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/22/2026 | SeverityHigh |
CVE-2026-65915NLTK before 3.10.0 Arbitrary File Read via FileSystemPathPointer | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/22/2026 | SeverityHigh |
CVE-2026-63312NLTK StreamBackedCorpusView Bypasses pathsec.ENFORCE Arbitrary File Read | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/22/2026 | SeverityHigh |
CVE-2026-63311NLTK before 3.10.0 SSRF via DNS Resolution Failure | Exploitation statusNot known exploited | FixYes | Affected productnltk | Published08/22/2026 | SeverityMedium |
CVE-2026-63310 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published08/22/2026 | SeverityUnknown |
CVE-2026-62388NLTK before 3.10.0 Insecure Default Configuration in pathsec.py | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/22/2026 | SeverityHigh |
CVE-2026-62385NLTK 3.9.4 Path Traversal via FrameNet and NKJP Readers | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/22/2026 | SeverityHigh |
CVE-2026-62384NLTK FramenetCorpusReader Symlink Sandbox Bypass before 3.10.2 | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/22/2026 | SeverityHigh |
CVE-2026-62383nltk IPIPANCorpusReader Symlink Arbitrary File Read | Exploitation statusNot known exploited | FixYes | Affected productnltk | Published08/22/2026 | SeverityMedium |
CVE-2026-71514NLTK 3.9.4 through 3.10.2 Path Traversal via CrubadanCorpusReader pathsec Bypass | Exploitation statusNot known exploited | FixYes | Affected productnltk | Published08/22/2026 | SeverityLow |
CVE-2026-71513NLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name Bypass | Exploitation statusNot known exploited | FixYes | Affected productnltk | Published08/22/2026 | SeverityHigh |
CVE-2026-72818NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Input | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published08/20/2026 | SeverityHigh |
CVE-2026-12372Server-Side Request Forgery (SSRF) in nltk/nltk | Exploitation statusPublic exploit | FixNot confirmed | Affected productnltk/nltk | Published08/09/2026 | SeverityLow |
CVE-2026-12261Improper Access Control in nltk/nltk | Exploitation statusPublic exploit | FixNot confirmed | Affected productnltk/nltk | Published08/07/2026 | SeverityMedium |
CVE-2026-12259Improper Input Validation in nltk/nltk | Exploitation statusNot known exploited | FixNot confirmed | Affected productnltk/nltk | Published08/03/2026 | SeverityMedium |
CVE-2025-71408NLTK < 3.9.3 Eval Injection via collocations.py Command-Line Arguments | Exploitation statusPublic exploit | FixYes | Affected productntlk | Published07/24/2026 | SeverityHigh |
CVE-2026-12252Untrusted JAR Code Execution in Multiple Stanford Interface Classes in nltk/nltk | Exploitation statusPublic exploit | FixNot confirmed | Affected productnltk/nltk | Published07/04/2026 | SeverityHigh |
CVE-2026-12243 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published06/30/2026 | SeverityUnknown |
CVE-2026-54293NLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read | Exploitation statusPublic exploit | FixYes | Affected productnltk | Published06/22/2026 | SeverityHigh |
CVE-2026-12199Unauthenticated Denial of Service in nltk.app.wordnet_app | Exploitation statusPublic exploit | FixNot confirmed | Affected productnltk/nltk | Published06/17/2026 | SeverityHigh |
CVE-2026-33236NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite | Exploitation statusPublic exploit | FixNot confirmed | Affected productnltk | Published03/20/2026 | SeverityHigh |
CVE-2026-33231NLTK has unauthenticated remote shutdown in nltk.app.wordnet_app | Exploitation statusPublic exploit | FixNot confirmed | Affected productnltk | Published03/20/2026 | SeverityHigh |
CVE-2026-33230nltk Vulnerable to Cross-site Scripting | Exploitation statusPublic exploit | FixNot confirmed | Affected productnltk | Published03/20/2026 | SeverityMedium |
CVE-2026-0846Arbitrary File Read via Absolute Path Input in nltk.util.filestring() | Exploitation statusPublic exploit | FixNot confirmed | Affected productnltk/nltk | Published03/09/2026 | SeverityHigh |
CVE-2026-0848Arbitrary Code Execution in NLTK StanfordSegmenter via Untrusted JAR Loading | Exploitation statusPublic exploit | FixNot confirmed | Affected productnltk/nltk | Published03/05/2026 | SeverityCritical |
CVE-2026-0847Path Traversal in nltk/nltk | Exploitation statusPublic exploit | FixNot confirmed | Affected productnltk/nltk | Published03/04/2026 | SeverityHigh |
CVE-2025-14009Zip Slip Vulnerability in nltk/nltk Leading to Remote Code Execution | Exploitation statusPublic exploit | FixNot confirmed | Affected productnltk/nltk | Published02/18/2026 | SeverityCritical |
CVE-2021-3842Inefficient Regular Expression Complexity in nltk/nltk | Exploitation statusNot confirmed | FixYes | Affected productnltk/nltk | Published01/04/2022 | SeverityHigh |
CVE-2021-43854Inefficient Regular Expression Complexity in nltk | Exploitation statusNot confirmed | FixNot confirmed | Affected productnltk | Published12/23/2021 | SeverityHigh |
CVE-2021-3828Inefficient Regular Expression Complexity in nltk/nltk | Exploitation statusNot confirmed | FixNot confirmed | Affected productnltk/nltk | Published09/27/2021 | SeverityHigh |
CVE-2019-14751 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published08/22/2019 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan