Vulnerabilities in nltk
15 resultsVexday analysis
A biblioteca NLTK apresenta 14 vulnerabilidades registradas, com 4 publicadas nos últimos 90 dias, indicando risco recente e continuado; nenhuma está sob exploração ativa conhecida, mas a fraqueza dominante (CWE-22: Path Traversal) sugere potencial para contaminação de dados ou acesso não autorizado. Com apenas 1 vulnerabilidade crítica, o risco é moderado, porém demanda atenção à atualização contínua dado o padrão de novas descobertas.
CVE-2021-43854HIGHInefficient Regular Expression Complexity in nltkEPSS 2.7%CVE-2021-3828HIGHInefficient Regular Expression Complexity in nltk/nltkEPSS 1.7%CVE-2021-3842HIGHInefficient Regular Expression Complexity in nltk/nltkEPSS 1.5%CVE-2026-0847HIGHPath Traversal in nltk/nltkEPSS 0.9%CVE-2026-33231HIGHNLTK has unauthenticated remote shutdown in nltk.app.wordnet_appEPSS 0.9%CVE-2026-0848CRITICALArbitrary Code Execution in NLTK StanfordSegmenter via Untrusted JAR LoadingEPSS 0.8%CVE-2025-14009HIGHZip Slip Vulnerability in nltk/nltk Leading to Remote Code ExecutionEPSS 0.8%CVE-2026-12243HIGHPath Traversal via Percent-Encoding in nltk.data.find() and nltk.data.load()EPSS 0.6%CVE-2026-33236HIGHNLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File OverwriteEPSS 0.6%CVE-2026-54293HIGHNLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File ReadEPSS 0.6%CVE-2026-0846HIGHArbitrary File Read via Absolute Path Input in nltk.util.filestring()EPSS 0.4%CVE-2026-33230MEDIUMnltk Vulnerable to Cross-site ScriptingEPSS 0.3%CVE-2026-12199HIGHUnauthenticated Denial of Service in nltk.app.wordnet_appEPSS 0.3%CVE-2026-12252HIGHUntrusted JAR Code Execution in Multiple Stanford Interface Classes in nltk/nltkEPSS 0.2%CVE-2026-12259MEDIUMImproper Input Validation in nltk/nltkEPSS 0.1%