CVEs we hold for Nltk
Records whose assigning authority named Nltk as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-81727NLTK before 3.10.3 Hardlink File Overwrite via downloadernltk CVE-2026-81726NLTK through 3.10.3 Path Traversal via Model-Artifact APIsnltk CVE-2026-81725NLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReadernltk CVE-2026-81724NLTK before 3.10.3 Denial of Service via Uncontrolled Recursionnltk CVE-2026-81723NLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusViewnltk CVE-2026-80206NLTK 3.10.2 Regular Expression Denial of Service via tgrepnltk CVE-2026-80205NLTK before 3.10.0 ReDoS via Text.findall() unvalidated regexnltk CVE-2026-79676NLTK before 3.10.3 Path Traversal via Symlink Bypassnltk CVE-2026-79675NLTK before 3.10.3 JVM Argument Injection via Per-Call Optionsnltk CVE-2026-79674NLTK 3.10.2 Path Traversal via corpus-reader constructorsnltk CVE-2026-79657NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserializationnltk CVE-2026-78683NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserializationnltk CVE-2026-78681NLTK before 3.10.3 Entity Expansion DoS via ElementTreenltk CVE-2026-78680NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binarynltk CVE-2026-72818NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Inputnltk CVE-2026-71514NLTK 3.9.4 through 3.10.2 Path Traversal via CrubadanCorpusReader pathsec Bypassnltk CVE-2026-71513NLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name Bypassnltk CVE-2026-66393NLTK before 3.9.4 Denial of Service via JSONTaggedDecodernltk CVE-2026-65915NLTK before 3.10.0 Arbitrary File Read via FileSystemPathPointernltk CVE-2026-63312NLTK StreamBackedCorpusView Bypasses pathsec.ENFORCE Arbitrary File Readnltk CVE-2026-63310NLTK before 3.9.3 Missing Post-Download Integrity Verificationnltk CVE-2026-62388NLTK before 3.10.0 Insecure Default Configuration in pathsec.pynltk CVE-2026-62385NLTK 3.9.4 Path Traversal via FrameNet and NKJP Readersnltk CVE-2026-62384NLTK FramenetCorpusReader Symlink Sandbox Bypass before 3.10.2nltk CVE-2026-54293NLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Readnltk CVE-2026-33236NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwritenltk CVE-2026-33231NLTK has unauthenticated remote shutdown in nltk.app.wordnet_appnltk CVE-2026-12372Server-Side Request Forgery (SSRF) in nltk/nltknltk/nltk CVE-2026-12252Untrusted JAR Code Execution in Multiple Stanford Interface Classes in nltk/nltknltk/nltk CVE-2026-12199Unauthenticated Denial of Service in nltk.app.wordnet_appnltk/nltk CVE-2026-0848Arbitrary Code Execution in NLTK StanfordSegmenter via Untrusted JAR Loadingnltk/nltk CVE-2026-0846Arbitrary File Read via Absolute Path Input in nltk.util.filestring()nltk/nltk CVE-2025-14009Zip Slip Vulnerability in nltk/nltk Leading to Remote Code Executionnltk/nltk CVE-2021-3842Inefficient Regular Expression Complexity in nltk/nltknltk/nltk CVE-2021-3828Inefficient Regular Expression Complexity in nltk/nltknltk/nltk 45 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.