Information on source package nltk

Available versions

ReleaseVersion
bullseye3.5-1
bookworm3.8-1
trixie3.9.1-2
forky3.10.1-1
sid3.10.3-1

Open issues

BugbullseyebookwormtrixieforkysidDescription
CVE-2026-54293vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNLTK (Natural Language Toolkit) is a suite of open source Python modul ...
CVE-2026-33236vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedNLTK (Natural Language Toolkit) is a suite of open source Python modul ...
CVE-2026-33231vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedNLTK (Natural Language Toolkit) is a suite of open source Python modul ...
CVE-2026-33230vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedNLTK (Natural Language Toolkit) is a suite of open source Python modul ...
CVE-2026-12876vulnerablevulnerablevulnerablevulnerablevulnerable
CVE-2026-12841vulnerablevulnerablevulnerable (no DSA)vulnerablefixed
CVE-2026-12372vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableA Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk ...
CVE-2026-12261vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableA vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 al ...
CVE-2026-12259vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableIn nltk version 3.9.4, the `nltk.downloader.Downloader._download_packa ...
CVE-2026-12252vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedIn nltk/nltk versions 3.9.3 and earlier, five Stanford interface class ...
CVE-2026-12243vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablevulnerableNLTK version 3.9.4 is vulnerable to a path traversal attack due to an ...
CVE-2026-12199vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablevulnerableA vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows u ...
CVE-2026-12074vulnerablevulnerablevulnerable (no DSA)fixedfixed
CVE-2026-12072vulnerablevulnerablevulnerable (no DSA)fixedfixed
CVE-2026-12061vulnerablevulnerablevulnerable (no DSA)fixedfixed
CVE-2026-0848vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedNLTK versions <=3.9.2 are vulnerable to arbitrary code execution due t ...
CVE-2026-0847vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedA vulnerability in NLTK versions up to and including 3.9.2 allows arbi ...
CVE-2026-0846vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedA vulnerability in the `filestring()` function of the `nltk.util` modu ...
CVE-2025-71408vulnerablevulnerablevulnerable (no DSA)fixedfixedNLTK (Natural Language Toolkit) before version 3.9.3 contains an eval ...
CVE-2025-14009vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedA critical vulnerability exists in the NLTK downloader component of nl ...
CVE-2024-39705vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)fixedfixedfixedNLTK through 3.8.1 allows remote code execution if untrusted packages ...
CVE-2021-43854vulnerable (no DSA)fixedfixedfixedfixedNLTK (Natural Language Toolkit) is a suite of open source Python modul ...
CVE-2021-3842vulnerable (no DSA)fixedfixedfixedfixednltk is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3828vulnerable (no DSA)fixedfixedfixedfixednltk is vulnerable to Inefficient Regular Expression Complexity

Resolved issues

BugDescription
CVE-2019-14751NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, a ...

Search for package or bug name: Reporting problems