Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3871
  • PyPI/nltk
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()` 10 Sep
  • Fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-3869
  • PyPI/nltk
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars 10 Sep
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-3868
  • PyPI/nltk
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary 10 Sep
  • Fix available
  • Severity - 8.5 (High)
PYSEC-2026-3867
  • PyPI/nltk
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution 10 Sep
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-3870
  • PyPI/nltk
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking 10 Sep
  • Fix available
  • Severity - 8.7 (High)
GHSA-8mpw-7fpc-4gqj
  • PyPI/nltk
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks 08 Sep
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-w3v8-gmh9-3wv7
  • PyPI/nltk
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions 08 Sep
  • Fix available
  • Severity - 8.2 (High)
GHSA-rrv8-h7p8-rx55
  • PyPI/nltk
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions 08 Sep
  • Fix available
  • Severity - 8.7 (High)
GHSA-3gq4-3j92-5w49
  • PyPI/nltk
NLTK: Corpus Reader Sandbox Bypass 08 Sep
  • Fix available
  • Severity - 8.8 (High)
GHSA-p4rw-rvv2-7xwr
  • PyPI/nltk
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement 08 Sep
  • Fix available
  • Severity - 8.2 (High)
GHSA-x99w-6fgc-pmfw
  • PyPI/nltk
NLTK: Allowlisted pickle loaders still permit code execution in current source 08 Sep
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-97qj-x29f-37w7
  • PyPI/nltk
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses 08 Sep
  • Fix available
  • Severity - 8.7 (High)
GHSA-6ww7-3frv-cqxh
  • PyPI/nltk
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured 08 Sep
  • Fix available
  • Severity - 8.7 (High)
GHSA-rhp5-r9x4-f5g2
  • PyPI/nltk
NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution 08 Sep
  • Fix available
  • Severity - 9.4 (Critical)
GHSA-3hhw-38pf-pxj6
  • PyPI/nltk
NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely 08 Sep
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-f833-7jw8-xwrv
  • PyPI/nltk
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292) 08 Sep
  • Fix available
  • Severity - 8.7 (High)