Vulnerabilidades em nltk

44 resultados
Análise Vexday

A biblioteca NLTK apresenta 14 vulnerabilidades registradas, com 4 publicadas nos últimos 90 dias, indicando risco recente e continuado; nenhuma está sob exploração ativa conhecida, mas a fraqueza dominante (CWE-22: Path Traversal) sugere potencial para contaminação de dados ou acesso não autorizado. Com apenas 1 vulnerabilidade crítica, o risco é moderado, porém demanda atenção à atualização contínua dado o padrão de novas descobertas.

CVE-2021-43854HIGHInefficient Regular Expression Complexity in nltkEPSS 2.7%CVE-2021-3828HIGHInefficient Regular Expression Complexity in nltk/nltkEPSS 1.7%CVE-2021-3842HIGHInefficient Regular Expression Complexity in nltk/nltkEPSS 1.5%CVE-2026-33231HIGHNLTK has unauthenticated remote shutdown in nltk.app.wordnet_appEPSS 1.2%CVE-2026-79657CRITICALNLTK before 3.10.3 Remote Code Execution via Unsafe Pickle DeserializationEPSS 1.2%CVE-2026-0847HIGHPath Traversal in nltk/nltkEPSS 0.9%CVE-2026-0848CRITICALArbitrary Code Execution in NLTK StanfordSegmenter via Untrusted JAR LoadingEPSS 0.8%CVE-2025-14009HIGHZip Slip Vulnerability in nltk/nltk Leading to Remote Code ExecutionEPSS 0.8%CVE-2026-71513HIGHNLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name BypassEPSS 0.8%CVE-2026-54293HIGHNLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File ReadEPSS 0.6%CVE-2026-33236HIGHNLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File OverwriteEPSS 0.6%CVE-2026-63312HIGHNLTK StreamBackedCorpusView Bypasses pathsec.ENFORCE Arbitrary File ReadEPSS 0.6%CVE-2026-62384HIGHNLTK FramenetCorpusReader Symlink Sandbox Bypass before 3.10.2EPSS 0.6%CVE-2026-72818HIGHNLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like InputEPSS 0.5%CVE-2026-80205HIGHNLTK before 3.10.0 ReDoS via Text.findall() unvalidated regexEPSS 0.5%CVE-2026-62388HIGHNLTK before 3.10.0 Insecure Default Configuration in pathsec.pyEPSS 0.5%CVE-2026-0846HIGHArbitrary File Read via Absolute Path Input in nltk.util.filestring()EPSS 0.4%CVE-2026-79675CRITICALNLTK before 3.10.3 JVM Argument Injection via Per-Call OptionsEPSS 0.4%CVE-2026-62385HIGHNLTK 3.9.4 Path Traversal via FrameNet and NKJP ReadersEPSS 0.4%CVE-2026-66393HIGHNLTK before 3.9.4 Denial of Service via JSONTaggedDecoderEPSS 0.4%