| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-81727 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.10.3 contain a filesystem containment bypass vu ... |
| CVE-2026-81726 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | NLTK through 3.10.3 contains a path traversal vulnerability in model-a ... |
| CVE-2026-81725 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK before 3.10.3 contains a regular expression denial of service vul ... |
| CVE-2026-81724 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in ... |
| CVE-2026-81723 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnera ... |
| CVE-2026-81722 | vulnerable | vulnerable (no DSA) | fixed | fixed | nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an ... |
| CVE-2026-80206 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK before 3.10.3 contains a regular expression denial of service (Re ... |
| CVE-2026-80205 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.10.0 contain a regular expression denial of ser ... |
| CVE-2026-79676 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.10.3 contain a path traversal vulnerability in ... |
| CVE-2026-79675 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK before 3.10.3 fails to validate JVM options passed through the pe ... |
| CVE-2026-79674 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.10.3 contain a path sandbox bypass vulnerabilit ... |
| CVE-2026-79657 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.10.3 contain a remote code execution vulnerabil ... |
| CVE-2026-78683 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pick ... |
| CVE-2026-78682 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK before 3.10.3 contains a server-side request forgery vulnerabilit ... |
| CVE-2026-78681 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in ... |
| CVE-2026-78680 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.10.3 fail to use validated absolute paths when ... |
| CVE-2026-72818 | vulnerable | vulnerable (no DSA) | fixed | fixed | The URLS regular expression in nltk/tokenize/casual.py, compiled into ... |
| CVE-2026-71514 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in C ... |
| CVE-2026-71513 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK before 3.10.3 contains a remote code execution vulnerability in A ... |
| CVE-2026-70626 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.9.4 contain a symlink escape vulnerability in C ... |
| CVE-2026-66393 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.9.4 contain an unbounded recursion vulnerabilit ... |
| CVE-2026-65915 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPoint ... |
| CVE-2026-63312 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK before 3.10.0 contains an arbitrary local file read vulnerability ... |
| CVE-2026-63311 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side ... |
| CVE-2026-63310 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK before 3.9.3 fails to verify file integrity after downloading pac ... |
| CVE-2026-62388 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, ca ... |
| CVE-2026-62385 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.10.0 contain a path traversal vulnerability in ... |
| CVE-2026-62384 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in ... |
| CVE-2026-62383 | vulnerable | vulnerable (no DSA) | fixed | fixed | nltk versions before 3.10.2 contain a symlink-based arbitrary file rea ... |
| CVE-2026-54293 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | NLTK (Natural Language Toolkit) is a suite of open source Python modul ... |
| CVE-2026-33236 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | NLTK (Natural Language Toolkit) is a suite of open source Python modul ... |
| CVE-2026-33231 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | NLTK (Natural Language Toolkit) is a suite of open source Python modul ... |
| CVE-2026-33230 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | NLTK (Natural Language Toolkit) is a suite of open source Python modul ... |
| CVE-2026-12876 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | |
| CVE-2026-12841 | vulnerable | vulnerable (no DSA) | fixed | fixed | |
| CVE-2026-12372 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk ... |
| CVE-2026-12261 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 al ... |
| CVE-2026-12259 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | In nltk version 3.9.4, the `nltk.downloader.Downloader._download_packa ... |
| CVE-2026-12252 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | In nltk/nltk versions 3.9.3 and earlier, five Stanford interface class ... |
| CVE-2026-12199 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable | vulnerable | A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows u ... |
| CVE-2026-12074 | vulnerable | vulnerable (no DSA) | fixed | fixed | |
| CVE-2026-12072 | vulnerable | vulnerable (no DSA) | fixed | fixed | |
| CVE-2026-12061 | vulnerable | vulnerable (no DSA) | fixed | fixed | |
| CVE-2026-0848 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due t ... |
| CVE-2026-0847 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | A vulnerability in NLTK versions up to and including 3.9.2 allows arbi ... |
| CVE-2026-0846 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | A vulnerability in the `filestring()` function of the `nltk.util` modu ... |
| CVE-2025-71408 | vulnerable | vulnerable (no DSA) | fixed | fixed | NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval ... |
| CVE-2025-14009 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | A critical vulnerability exists in the NLTK downloader component of nl ... |
| CVE-2024-39705 | vulnerable (no DSA, postponed) | fixed | fixed | fixed | NLTK through 3.8.1 allows remote code execution if untrusted packages ... |