Skip to content

nltk-3.9.1-py3-none-any.whl: 41 vulnerabilities (highest severity is: 10.0) #443

Description

@mend-bolt-for-github
Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (nltk version) Remediation Possible**
CVE-2026-0848 Critical 10.0 nltk-3.9.1-py3-none-any.whl Direct 3.9.3 ❌
CVE-2025-14009 Critical 10.0 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.9.3 ❌
CVE-2026-79675 Critical 9.8 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.10.3 ❌
CVE-2026-79657 Critical 9.8 nltk-3.9.1-py3-none-any.whl Direct 3.10.3 ❌
CVE-2026-78683 Critical 9.6 nltk-3.9.1-py3-none-any.whl Direct 3.10.0 ❌
CVE-2026-71513 High 8.8 nltk-3.9.1-py3-none-any.whl Direct 3.10.3 ❌
CVE-2026-12075 High 8.6 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.10.0 ❌
CVE-2026-0847 High 8.6 nltk-3.9.1-py3-none-any.whl Direct 3.9.3 ❌
CVE-2026-0846 High 8.6 nltk-3.9.1-py3-none-any.whl Direct 3.9.3 ❌
CVE-2026-79674 High 8.2 nltk-3.9.1-py3-none-any.whl Direct 3.10.3 ❌
CVE-2026-33236 High 8.1 nltk-3.9.1-py3-none-any.whl Direct N/A ❌
CVE-2026-78680 High 7.8 nltk-3.9.1-py3-none-any.whl Direct 3.10.3 ❌
CVE-2026-12252 High 7.8 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.9.4 ❌
CVE-2025-71408 High 7.8 nltk-3.9.1-py3-none-any.whl Direct 3.9.3 ❌
CVE-2026-81722 High 7.5 nltk-3.9.1-py3-none-any.whl Direct 3.10.3 ❌
CVE-2026-80205 High 7.5 nltk-3.9.1-py3-none-any.whl Direct 3.10.0 ❌
CVE-2026-78682 High 7.5 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.10.3 ❌
CVE-2026-78681 High 7.5 nltk-3.9.1-py3-none-any.whl Direct 3.10.3 ❌
CVE-2026-72818 High 7.5 nltk-3.9.1-py3-none-any.whl Direct 3.10.1 ❌
CVE-2026-66393 High 7.5 nltk-3.9.1-py3-none-any.whl Direct 3.9.4 ❌
CVE-2026-63312 High 7.5 nltk-3.9.1-py3-none-any.whl Direct 3.10.0 ❌
CVE-2026-62388 High 7.5 nltk-3.9.1-py3-none-any.whl Direct 3.10.0 ❌
CVE-2026-54293 High 7.5 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.10.0 ❌
CVE-2026-33231 High 7.5 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.9.4 ❌
CVE-2026-12199 High 7.5 nltk-3.9.1-py3-none-any.whl Direct 3.9.4 ❌
CVE-2026-12074 High 7.5 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.10.0 ❌
CVE-2026-12072 High 7.5 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.10.0 ❌
CVE-2026-12061 High 7.5 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.10.0 ❌
CVE-2026-81727 High 7.1 nltk-3.9.1-py3-none-any.whl Direct 3.10.3 ❌
CVE-2026-81726 High 7.0 nltk-3.9.1-py3-none-any.whl Direct N/A ❌
CVE-2026-65915 Medium 6.5 nltk-3.9.1-py3-none-any.whl Direct 3.10.0 ❌
CVE-2026-70626 Medium 6.2 nltk-3.9.1-py3-none-any.whl Direct 3.9.4 ❌
CVE-2026-33230 Medium 6.1 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.9.4 ❌
CVE-2026-80206 Medium 5.9 nltk-3.9.1-py3-none-any.whl Direct 3.10.3 ❌
CVE-2026-79676 Medium 5.9 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.10.3 ❌
CVE-2026-62385 Medium 5.9 nltk-3.9.1-py3-none-any.whl Direct 3.10.0 ❌
CVE-2026-81724 Medium 5.3 nltk-3.9.1-py3-none-any.whl Direct 3.10.3 ❌
CVE-2026-63311 Medium 5.3 nltk-3.9.1-py3-none-any.whl Direct 3.10.0 ❌
CVE-2026-12876 Medium 5.3 nltk-3.9.1-py3-none-any.whl Direct nltk - 3.10.3 ❌
CVE-2026-12261 Medium 5.3 nltk-3.9.1-py3-none-any.whl Direct 3.10.0 ❌
CVE-2026-12259 Medium 5.3 nltk-3.9.1-py3-none-any.whl Direct 3.10.0 ❌

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

Partial details (18 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.

CVE-2026-0848

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An attacker can supply or replace the JAR file, enabling the execution of arbitrary Java bytecode at import time. This vulnerability can be exploited through methods such as model poisoning, MITM attacks, or dependency poisoning, leading to remote code execution. The issue arises from the direct execution of the JAR file via subprocess with unvalidated classpath input, allowing malicious classes to execute when loaded by the JVM.

Publish Date: 2026-03-05

URL: CVE-2026-0848

CVSS 3 Score Details (10.0)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://huntr.com/bounties/08b109bb-ac24-403f-9422-1c246ce60202

Release Date: 2026-03-05

Fix Resolution: 3.9.3

Step up your Open Source Security Game with Mend here

CVE-2025-14009

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This allows attackers to craft malicious zip packages that, when downloaded and extracted by NLTK, can execute arbitrary code. The vulnerability arises because NLTK assumes all downloaded packages are trusted and extracts them without validation. If a malicious package contains Python files, such as init.py, these files are executed automatically upon import, leading to remote code execution. This issue can result in full system compromise, including file system access, network access, and potential persistence mechanisms.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-02-18

URL: CVE-2025-14009

CVSS 3 Score Details (10.0)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-7p94-766c-hgjp

Release Date: 2026-02-18

Fix Resolution: nltk - 3.9.3

Step up your Open Source Security Game with Mend here

CVE-2026-79675

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @⁠argfile to Stanford wrapper classes to achieve arbitrary code execution.

Publish Date: 2026-08-25

URL: CVE-2026-79675

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-m4rf-3fr8-xwx3

Release Date: 2026-08-25

Fix Resolution: nltk - 3.10.3

Step up your Open Source Security Game with Mend here

CVE-2026-79657

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading.

Publish Date: 2026-08-25

URL: CVE-2026-79657

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-x99w-6fgc-pmfw

Release Date: 2026-08-25

Fix Resolution: 3.10.3

Step up your Open Source Security Game with Mend here

CVE-2026-78683

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through WarningUnpickler, which does not override find_class() and therefore permits arbitrary class resolution. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code with the privileges of the user running the application. NLTK provides a RestrictedUnpickler for safe deserialization, but it is not used by production code paths. Fixed in 3.10.0.

Publish Date: 2026-08-25

URL: CVE-2026-78683

CVSS 3 Score Details (9.6)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: 3.10.0

Step up your Open Source Security Game with Mend here

CVE-2026-71513

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the model through allowlisted_pickle_load.

Publish Date: 2026-08-22

URL: CVE-2026-71513

CVSS 3 Score Details (8.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-22

Fix Resolution: 3.10.3

Step up your Open Source Security Game with Mend here

CVE-2026-12075

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

"nltk.pathsec" provides an SSRF filter that NLTK documents as a security control, blocking loopback, private, link-local, and multicast ranges (including obfuscated forms) and recommending strict "ENFORCE" mode for security-sensitive environments. The filter is bypassable by DNS rebinding: "validate_network_url()" resolves the hostname and checks the resulting IP, but the actual HTTP connection re-resolves the hostname independently at connect time and connects to that second result. The validated IP is never the one connected to. An attacker controlling DNS for a hostname (a TTL-0 rebinding record) returns a public IP for the validation lookup and an internal/loopback IP for the connection lookup, defeating the filter even under "nltk.pathsec.ENFORCE = True".

Publish Date: 2026-07-31

URL: CVE-2026-12075

CVSS 3 Score Details (8.6)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-qvv7-cg9c-w4x3

Release Date: 2026-07-31

Fix Resolution: nltk - 3.10.0

Step up your Open Source Security Game with Mend here

CVE-2026-0847

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fail to properly sanitize or validate file paths, enabling attackers to traverse directories and access sensitive files on the server. This issue is particularly critical in scenarios where user-controlled file inputs are processed, such as in machine learning APIs, chatbots, or NLP pipelines. Exploitation of this vulnerability can lead to unauthorized access to sensitive files, including system files, SSH private keys, and API tokens, and may potentially escalate to remote code execution when combined with other vulnerabilities.

Publish Date: 2026-03-04

URL: CVE-2026-0847

CVSS 3 Score Details (8.6)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-03-04

Fix Resolution: 3.9.3

Step up your Open Source Security Game with Mend here

CVE-2026-0846

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

A vulnerability in the "filestring()" function of the "nltk.util" module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input.

Publish Date: 2026-03-09

URL: CVE-2026-0846

CVSS 3 Score Details (8.6)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-03-09

Fix Resolution: 3.9.3

Step up your Open Source Security Game with Mend here

CVE-2026-79674

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary.

Publish Date: 2026-08-25

URL: CVE-2026-79674

CVSS 3 Score Details (8.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://www.mend.io/vulnerability-database/CVE-2026-79674

Release Date: 2026-08-25

Fix Resolution: 3.10.3

Step up your Open Source Security Game with Mend here

CVE-2026-33236

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the "subdir" and "id" attributes when processing remote XML index files. Attackers can control a remote XML index server to provide malicious values containing path traversal sequences (such as "../"), which can lead to arbitrary directory creation, arbitrary file creation, and arbitrary file overwrite. Commit 89fe2ec2c6bae6e2e7a46dad65cc34231976ed8a patches the issue.

Publish Date: 2026-03-20

URL: CVE-2026-33236

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Step up your Open Source Security Game with Mend here

CVE-2026-78680

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent.repr_svg, allowing attackers to execute arbitrary code by placing a malicious dot binary in the search path or current working directory. Attackers can exploit bare-name binary resolution on Windows via the current working directory or on Unix-like systems via relative PATH entries to execute their binary instead of the legitimate Graphviz tool.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-08-25

URL: CVE-2026-78680

CVSS 3 Score Details (7.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-6hwm-xvph-95vm

Release Date: 2026-08-25

Fix Resolution: 3.10.3

Step up your Open Source Security Game with Mend here

CVE-2026-12252

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These classes accept user-controllable JAR paths and execute them via the "java()" function, which invokes "subprocess.Popen()" without integrity verification. This vulnerability is identical to CVE-2026-0848, which was fixed for StanfordSegmenter by adding SHA256 verification. However, the fix was not applied to these additional classes, leaving them susceptible to arbitrary code execution when loading untrusted JAR files.

Publish Date: 2026-07-04

URL: CVE-2026-12252

CVSS 3 Score Details (7.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-9r6g-266r-89x4

Release Date: 2026-07-04

Fix Resolution: nltk - 3.9.4

Step up your Open Source Security Game with Mend here

CVE-2025-71408

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the main block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-07-24

URL: CVE-2025-71408

CVSS 3 Score Details (7.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-07-24

Fix Resolution: 3.9.3

Step up your Open Source Security Game with Mend here

CVE-2026-81722

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' characters on every call, and _measure() invokes it for each stem position, causing O(n^2) behavior. A single ~20-50 KB untrusted token consisting of a long run of the letter 'y' followed by a matching suffix (e.g., 'ness') can pin a CPU core for seconds to minutes, causing availability impact.

Publish Date: 2026-08-27

URL: CVE-2026-81722

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-27

Fix Resolution: 3.10.3

Step up your Open Source Security Game with Mend here

CVE-2026-80205

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers can supply crafted regex patterns that cause catastrophic backtracking, resulting in indefinite CPU saturation and denial of service to all users of the Python process.

Publish Date: 2026-08-26

URL: CVE-2026-80205

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-rrv8-h7p8-rx55

Release Date: 2026-08-26

Fix Resolution: 3.10.0

Step up your Open Source Security Game with Mend here

CVE-2026-78682

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that is never re-validated. An attacker can supply a validated public URL that the proxy forwards to an internal loopback-only service, allowing disclosure of internal HTTP resources, loading of forged downloader indexes, and installation of attacker-chosen package content.

Publish Date: 2026-08-25

URL: CVE-2026-78682

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-6ww7-3frv-cqxh

Release Date: 2026-08-25

Fix Resolution: nltk - 3.10.3

Step up your Open Source Security Game with Mend here

CVE-2026-78681

Vulnerable Library - nltk-3.9.1-py3-none-any.whl

Natural Language Toolkit

Library home page: https://files.pythonhosted.org/packages/4d/66/7d9e26593edda06e8cb531874633f7c2372279c3b0f46235539fe546df8b/nltk-3.9.1-py3-none-any.whl

Sample Path to Dependency File: /llm_core/.ws-temp-UUSECC-requirements.txt

Path to vulnerable library: /llm_core/.ws-temp-UUSECC-requirements.txt,/modules/text/module_text_llm/.ws-temp-YBCMOS-requirements.txt,/modules/programming/module_programming_winnowing/.ws-temp-MVCPIX-requirements.txt,/modules/programming/module_programming_llm/.ws-temp-QQXLZB-requirements.txt,/modules/modeling/module_modeling_llm/.ws-temp-FXAQNG-requirements.txt

Dependency Hierarchy:

  • ❌ nltk-3.9.1-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.

Publish Date: 2026-08-25

URL: CVE-2026-78681

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-97qj-x29f-37w7

Release Date: 2026-08-25

Fix Resolution: 3.10.3

Step up your Open Source Security Game with Mend here

Activity

  1. changed the title [-]nltk-3.9.1-py3-none-any.whl: 1 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 2 vulnerabilities (highest severity is: 10.0)[/+] on Mar 5, 2026
  2. changed the title [-]nltk-3.9.1-py3-none-any.whl: 2 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 3 vulnerabilities (highest severity is: 10.0)[/+] on Mar 9, 2026
  3. changed the title [-]nltk-3.9.1-py3-none-any.whl: 3 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 4 vulnerabilities (highest severity is: 10.0)[/+] on Mar 19, 2026
  4. changed the title [-]nltk-3.9.1-py3-none-any.whl: 4 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 6 vulnerabilities (highest severity is: 10.0)[/+] on Mar 19, 2026
  5. changed the title [-]nltk-3.9.1-py3-none-any.whl: 6 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 7 vulnerabilities (highest severity is: 10.0)[/+] on Mar 23, 2026
  6. zhaog100 commented on Mar 23, 2026

    @zhaog100

    /attempt

  7. zhaog100 commented on Mar 23, 2026

    @zhaog100

    /attempt

  8. changed the title [-]nltk-3.9.1-py3-none-any.whl: 7 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 8 vulnerabilities (highest severity is: 10.0)[/+] on Jun 16, 2026
  9. changed the title [-]nltk-3.9.1-py3-none-any.whl: 8 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 9 vulnerabilities (highest severity is: 10.0)[/+] on Jun 22, 2026
  10. changed the title [-]nltk-3.9.1-py3-none-any.whl: 9 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 10 vulnerabilities (highest severity is: 10.0)[/+] on Jun 30, 2026
  11. changed the title [-]nltk-3.9.1-py3-none-any.whl: 10 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 11 vulnerabilities (highest severity is: 10.0)[/+] on Jul 26, 2026
  12. changed the title [-]nltk-3.9.1-py3-none-any.whl: 11 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 15 vulnerabilities (highest severity is: 10.0)[/+] on Jul 31, 2026
  13. changed the title [-]nltk-3.9.1-py3-none-any.whl: 15 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 16 vulnerabilities (highest severity is: 10.0)[/+] on Aug 3, 2026
  14. changed the title [-]nltk-3.9.1-py3-none-any.whl: 16 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 17 vulnerabilities (highest severity is: 10.0)[/+] on Aug 9, 2026
  15. changed the title [-]nltk-3.9.1-py3-none-any.whl: 17 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 16 vulnerabilities (highest severity is: 10.0)[/+] on Aug 18, 2026
  16. changed the title [-]nltk-3.9.1-py3-none-any.whl: 16 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 17 vulnerabilities (highest severity is: 10.0)[/+] on Aug 21, 2026
  17. changed the title [-]nltk-3.9.1-py3-none-any.whl: 17 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 26 vulnerabilities (highest severity is: 10.0)[/+] on Aug 23, 2026
  18. changed the title [-]nltk-3.9.1-py3-none-any.whl: 26 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 29 vulnerabilities (highest severity is: 10.0)[/+] on Aug 25, 2026
  19. changed the title [-]nltk-3.9.1-py3-none-any.whl: 29 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 31 vulnerabilities (highest severity is: 10.0)[/+] on Aug 26, 2026
  20. changed the title [-]nltk-3.9.1-py3-none-any.whl: 31 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 33 vulnerabilities (highest severity is: 10.0)[/+] on Aug 27, 2026
  21. changed the title [-]nltk-3.9.1-py3-none-any.whl: 33 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 37 vulnerabilities (highest severity is: 10.0)[/+] on Aug 28, 2026
  22. changed the title [-]nltk-3.9.1-py3-none-any.whl: 37 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 38 vulnerabilities (highest severity is: 10.0)[/+] on Sep 2, 2026
  23. changed the title [-]nltk-3.9.1-py3-none-any.whl: 38 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 39 vulnerabilities (highest severity is: 10.0)[/+] on Sep 3, 2026
  24. changed the title [-]nltk-3.9.1-py3-none-any.whl: 39 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 41 vulnerabilities (highest severity is: 10.0)[/+] on Sep 8, 2026
  25. changed the title [-]nltk-3.9.1-py3-none-any.whl: 41 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 40 vulnerabilities (highest severity is: 10.0)[/+] on Sep 15, 2026
  26. changed the title [-]nltk-3.9.1-py3-none-any.whl: 40 vulnerabilities (highest severity is: 10.0)[/-] [+]nltk-3.9.1-py3-none-any.whl: 41 vulnerabilities (highest severity is: 10.0)[/+] on Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions