100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether nltk is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.5
PyPI

CVE-2026-12261

CVE-2026-12261

LOW 3.7
PyPI

CVE-2026-12372

CVE-2026-12372

UNKNOWN
PyPI

CVE-2026-12876

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

HIGH 7.5
PyPI

CVE-2026-72818

NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking

LOW 3.7
PyPI

CVE-2026-81723

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

HIGH 8.8
PyPI

CVE-2026-71513

NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

HIGH 7.8
PyPI

CVE-2026-78680

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

LOW 3.7
PyPI

CVE-2026-81723

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

UNKNOWN
PyPI

CVE-2026-12876

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

HIGH 7.5
PyPI

CVE-2026-72818

NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking

HIGH 7.8
PyPI

CVE-2026-78680

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

HIGH 8.8
PyPI

CVE-2026-71513

NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

MEDIUM 6.5
PyPI

CVE-2026-12259

CVE-2026-12259

HIGH 7.1
PyPI

CVE-2026-12259

Duplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

MEDIUM 5.3
PyPI

CVE-2026-12259

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

LOW 3.3
PyPI

CVE-2026-71514

CVE-2026-71514

CRITICAL 9.8
PyPI

CVE-2026-79675

NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)

MEDIUM 5.3
PyPI

CVE-2026-81724

NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input

HIGH 7.1
PyPI

CVE-2026-81727

NLTK: Downloader.download follows hardlinks and overwrites outside-root files

HIGH 7.5
PyPI

GHSA-cv2g-m8rr-888c

Duplicate Advisory: Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS

LOW 2.5
PyPI

CVE-2026-71514

NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure

HIGH 7.5
PyPI

GHSA-8x48-8g7j-rqxp

Duplicate Advisory: Quadratic-time DoS in PorterStemmer via long runs of 'y'

HIGH 7.1
PyPI

GHSA-4xw3-jf9x-x7mf

Duplicate Advisory: Downloader.download follows hardlinks and overwrites outside-root files

HIGH 7.5
PyPI

CVE-2026-12072

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

HIGH 7.5
PyPI

CVE-2026-54293

Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read

UNKNOWN
PyPI

CVE-2026-81722

NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'

MEDIUM 5.3
PyPI

GHSA-pf76-q698-37v8

Duplicate Advisory: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input

LOW 3.7
PyPI

GHSA-hqv3-xm29-p9hq

Duplicate Advisory: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

HIGH 7.5
PyPI

CVE-2026-12074

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

HIGH 8.6
PyPI

CVE-2026-12075

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

HIGH 7.5
PyPI

CVE-2026-12061

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

HIGH 7.5
PyPI

GHSA-q5h6-fcf5-49g9

Duplicate Advisory: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences

UNKNOWN
PyPI

CVE-2026-66393

Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS

HIGH 7.5
PyPI

CVE-2026-33231

Unauthenticated remote shutdown in nltk.app.wordnet_app

MEDIUM 6.1
PyPI

CVE-2026-33230

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk

HIGH 8.1
PyPI

CVE-2026-33236

NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite

CRITICAL 10.0
PyPI

CVE-2025-14009

NLTK has a Zip Slip Vulnerability

HIGH 7.5
PyPI

CVE-2024-39705

ntlk unsafe deserialization vulnerability

UNKNOWN
PyPI

CVE-2026-81725

NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks

HIGH 7.5
PyPI

CVE-2026-80205

NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions

UNKNOWN
PyPI

CVE-2026-80206

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

HIGH 7.5
PyPI

GHSA-2rrw-hpqm-36pv

Duplicate Advisory: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions

UNKNOWN
PyPI

CVE-2026-79674

NLTK: Corpus Reader Sandbox Bypass

UNKNOWN
PyPI

CVE-2026-79657

NLTK: Allowlisted pickle loaders still permit code execution in current source

UNKNOWN
PyPI

CVE-2026-79676

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

UNKNOWN
PyPI

CVE-2026-78683

NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

UNKNOWN
PyPI

CVE-2026-78681

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

UNKNOWN
PyPI

CVE-2026-78682

NLTK: pathsec SSRF protection can be bypassed when a proxy is configured

HIGH 7.5
PyPI

CVE-2026-62384

NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)

MEDIUM 5.9
PyPI

GHSA-qp76-pq9f-gr9m

Duplicate Advisory: Stable FrameNet and NKJP readers parse outside-root XML in 3.9.4

MEDIUM 5.5
PyPI

CVE-2026-62383

NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely

MEDIUM 5.9
PyPI

CVE-2026-62385

NLTK: Stable FrameNet and NKJP readers parse outside-root XML

UNKNOWN
PyPI

CVE-2026-63312

NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read

MEDIUM 6.5
PyPI

CVE-2026-65915

NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol

MEDIUM 6.2
PyPI

CVE-2026-70626

NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root

UNKNOWN
PyPI

CVE-2026-62384

CVE-2026-62384

HIGH 7.5
PyPI

GHSA-8vh5-mgjj-w6hg

Duplicate Advisory: [CWE-1188] Default ENFORCE=False Disables All pathsec Security Controls

UNKNOWN
PyPI

CVE-2026-62388

NLTK: Default ENFORCE=False Disables All pathsec Security Controls

MEDIUM 5.3
PyPI

GHSA-qg9p-xrhj-435m

Duplicate Advisory: nltk: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure

UNKNOWN
PyPI

CVE-2026-63311

NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure

HIGH 7.5
PyPI

GHSA-qq3h-cgj8-w3fx

Duplicate Advisory: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)

MEDIUM 5.9
PyPI

GHSA-vf76-f5cp-9846

Duplicate Advisory: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

MEDIUM 6.5
PyPI

GHSA-79ph-w9m5-4v5m

Duplicate Advisory: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol

MEDIUM 5.9
PyPI

GHSA-w5q8-6jpp-4246

Duplicate Advisory: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

MEDIUM 5.5
PyPI

GHSA-343m-9fqq-97c7

Duplicate Advisory: NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely

HIGH 8.2
PyPI

GHSA-rcw8-9qrw-27m2

Duplicate Advisory: NLTK: Corpus Reader Sandbox Bypass

MEDIUM 6.2
PyPI

GHSA-8h9m-22mv-qv5r

Duplicate Advisory: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root

HIGH 7.5
PyPI

GHSA-jx89-3qg8-p2mr

Duplicate Advisory: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses (CWE-776)

CRITICAL 9.6
PyPI

GHSA-gx65-c5hj-vpv5

Duplicate Advisory: [CWE-502] Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

CRITICAL 9.8
PyPI

GHSA-vp9c-2pjm-8925

Duplicate Advisory: Allowlisted pickle loaders still permit code execution in current source

LOW 3.7
PyPI

GHSA-3m7f-6hxv-6796

Duplicate Advisory: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks

HIGH 7.5
PyPI

GHSA-crp9-r7rq-c8cg

Duplicate Advisory: pathsec SSRF protection can be bypassed when a proxy is configured

HIGH 7.5
PyPI

GHSA-8w48-h75v-cxpv

Duplicate Advisory: Security Report: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read

HIGH 7.0
PyPI

CVE-2026-81726

NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots

HIGH 7.0
PyPI

GHSA-hqj7-phwp-c3fp

Duplicate Advisory: Model-artifact APIs bypass pathsec and touch files outside allowed roots

UNKNOWN
PyPI

CVE-2026-81725

CVE-2026-81725

UNKNOWN
PyPI

CVE-2026-79675

CVE-2026-79675

UNKNOWN
PyPI

CVE-2026-80206

CVE-2026-80206

UNKNOWN
PyPI

CVE-2026-78681

CVE-2026-78681

UNKNOWN
PyPI

CVE-2026-80205

CVE-2026-80205

CRITICAL 9.8
PyPI

GHSA-3h2g-j4wp-7qqq

Duplicate Advisory: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)

MEDIUM 5.3
PyPI

GHSA-pv39-qrfq-g8gc

Duplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

HIGH 7.8
PyPI

GHSA-54xp-3ww7-6wjg

Duplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427)

UNKNOWN
PyPI

CVE-2026-79676

CVE-2026-79676

UNKNOWN
PyPI

CVE-2026-63312

CVE-2026-63312

UNKNOWN
PyPI

CVE-2026-70626

CVE-2026-70626

UNKNOWN
PyPI

CVE-2026-79657

CVE-2026-79657

UNKNOWN
PyPI

CVE-2026-81722

CVE-2026-81722

UNKNOWN
PyPI

CVE-2026-81727

CVE-2026-81727

UNKNOWN
PyPI

CVE-2026-78682

CVE-2026-78682

UNKNOWN
PyPI

CVE-2026-65915

CVE-2026-65915

UNKNOWN
PyPI

CVE-2026-81724

CVE-2026-81724

UNKNOWN
PyPI

CVE-2026-81726

CVE-2026-81726

HIGH 7.5
PyPI

CVE-2026-62385

CVE-2026-62385

UNKNOWN
PyPI

CVE-2026-79674

CVE-2026-79674

UNKNOWN
PyPI

CVE-2026-78683

CVE-2026-78683

UNKNOWN
PyPI

CVE-2026-62383

CVE-2026-62383

UNKNOWN
PyPI

CVE-2026-66393

CVE-2026-66393

UNKNOWN
PyPI

CVE-2026-63311

CVE-2026-63311

UNKNOWN
PyPI

CVE-2026-62388

CVE-2026-62388

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes