Information on source package nltk

Available versions

ReleaseVersion
bookworm3.8-1
trixie3.9.1-2
forky3.10.3-1
sid3.10.3-1

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-81727vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.10.3 contain a filesystem containment bypass vu ...
CVE-2026-81726vulnerablevulnerable (no DSA)vulnerablevulnerableNLTK through 3.10.3 contains a path traversal vulnerability in model-a ...
CVE-2026-81725vulnerablevulnerable (no DSA)fixedfixedNLTK before 3.10.3 contains a regular expression denial of service vul ...
CVE-2026-81724vulnerablevulnerable (no DSA)fixedfixedNLTK before 3.10.3 contains an uncontrolled recursion vulnerability in ...
CVE-2026-81723vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnera ...
CVE-2026-81722vulnerablevulnerable (no DSA)fixedfixednltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an ...
CVE-2026-80206vulnerablevulnerable (no DSA)fixedfixedNLTK before 3.10.3 contains a regular expression denial of service (Re ...
CVE-2026-80205vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.10.0 contain a regular expression denial of ser ...
CVE-2026-79676vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.10.3 contain a path traversal vulnerability in ...
CVE-2026-79675vulnerablevulnerable (no DSA)fixedfixedNLTK before 3.10.3 fails to validate JVM options passed through the pe ...
CVE-2026-79674vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.10.3 contain a path sandbox bypass vulnerabilit ...
CVE-2026-79657vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.10.3 contain a remote code execution vulnerabil ...
CVE-2026-78683vulnerablevulnerable (no DSA)fixedfixedNLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pick ...
CVE-2026-78682vulnerablevulnerable (no DSA)fixedfixedNLTK before 3.10.3 contains a server-side request forgery vulnerabilit ...
CVE-2026-78681vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in ...
CVE-2026-78680vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.10.3 fail to use validated absolute paths when ...
CVE-2026-72818vulnerablevulnerable (no DSA)fixedfixedThe URLS regular expression in nltk/tokenize/casual.py, compiled into ...
CVE-2026-71514vulnerablevulnerable (no DSA)fixedfixedNLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in C ...
CVE-2026-71513vulnerablevulnerable (no DSA)fixedfixedNLTK before 3.10.3 contains a remote code execution vulnerability in A ...
CVE-2026-70626vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.9.4 contain a symlink escape vulnerability in C ...
CVE-2026-66393vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.9.4 contain an unbounded recursion vulnerabilit ...
CVE-2026-65915vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.10.0 contain a logic bug in FileSystemPathPoint ...
CVE-2026-63312vulnerablevulnerable (no DSA)fixedfixedNLTK before 3.10.0 contains an arbitrary local file read vulnerability ...
CVE-2026-63311vulnerablevulnerable (no DSA)fixedfixedNLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side ...
CVE-2026-63310vulnerablevulnerable (no DSA)fixedfixedNLTK before 3.9.3 fails to verify file integrity after downloading pac ...
CVE-2026-62388vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, ca ...
CVE-2026-62385vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.10.0 contain a path traversal vulnerability in ...
CVE-2026-62384vulnerablevulnerable (no DSA)fixedfixedNLTK versions before 3.10.2 contain a symlink-based sandbox bypass in ...
CVE-2026-62383vulnerablevulnerable (no DSA)fixedfixednltk versions before 3.10.2 contain a symlink-based arbitrary file rea ...
CVE-2026-54293vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNLTK (Natural Language Toolkit) is a suite of open source Python modul ...
CVE-2026-33236vulnerable (no DSA)vulnerable (no DSA)fixedfixedNLTK (Natural Language Toolkit) is a suite of open source Python modul ...
CVE-2026-33231vulnerable (no DSA)vulnerable (no DSA)fixedfixedNLTK (Natural Language Toolkit) is a suite of open source Python modul ...
CVE-2026-33230vulnerable (no DSA)vulnerable (no DSA)fixedfixedNLTK (Natural Language Toolkit) is a suite of open source Python modul ...
CVE-2026-12876vulnerablevulnerable (no DSA)vulnerablevulnerable
CVE-2026-12841vulnerablevulnerable (no DSA)fixedfixed
CVE-2026-12372vulnerablevulnerable (no DSA)vulnerablevulnerableA Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk ...
CVE-2026-12261vulnerablevulnerable (no DSA)vulnerablevulnerableA vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 al ...
CVE-2026-12259vulnerablevulnerable (no DSA)vulnerablevulnerableIn nltk version 3.9.4, the `nltk.downloader.Downloader._download_packa ...
CVE-2026-12252vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedIn nltk/nltk versions 3.9.3 and earlier, five Stanford interface class ...
CVE-2026-12199vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablevulnerableA vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows u ...
CVE-2026-12074vulnerablevulnerable (no DSA)fixedfixed
CVE-2026-12072vulnerablevulnerable (no DSA)fixedfixed
CVE-2026-12061vulnerablevulnerable (no DSA)fixedfixed
CVE-2026-0848vulnerable (no DSA)vulnerable (no DSA)fixedfixedNLTK versions <=3.9.2 are vulnerable to arbitrary code execution due t ...
CVE-2026-0847vulnerable (no DSA)vulnerable (no DSA)fixedfixedA vulnerability in NLTK versions up to and including 3.9.2 allows arbi ...
CVE-2026-0846vulnerable (no DSA)vulnerable (no DSA)fixedfixedA vulnerability in the `filestring()` function of the `nltk.util` modu ...
CVE-2025-71408vulnerablevulnerable (no DSA)fixedfixedNLTK (Natural Language Toolkit) before version 3.9.3 contains an eval ...
CVE-2025-14009vulnerable (no DSA)vulnerable (no DSA)fixedfixedA critical vulnerability exists in the NLTK downloader component of nl ...
CVE-2024-39705vulnerable (no DSA, postponed)fixedfixedfixedNLTK through 3.8.1 allows remote code execution if untrusted packages ...

Resolved issues

BugDescription
CVE-2021-43854NLTK (Natural Language Toolkit) is a suite of open source Python modul ...
CVE-2021-3842nltk is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3828nltk is vulnerable to Inefficient Regular Expression Complexity
CVE-2019-14751NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, a ...

Search for package or bug name: Reporting problems