© 2025-2026 PySpect
No release of nltk is currently known to be free of vulnerabilities.
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks
Fixed in: 3.10.3
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
Fixed in: 3.10.3
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
Fixed in: 3.10.0
NLTK: Corpus Reader Sandbox Bypass
Fixed in: 3.10.3
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
Fixed in: 3.10.3
NLTK: Allowlisted pickle loaders still permit code execution in current source
Fixed in: 3.10.3
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
Fixed in: 3.10.3
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured
Fixed in: 3.10.3
NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
Fixed in: 3.10.0
NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
Fixed in: 3.10.2
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
Fixed in: 3.10.2
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
Fixed in: 3.10.0
NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
Fixed in: 3.9.3
NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read
Fixed in: 3.10.0
NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol
Fixed in: 3.10.0
NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root
Fixed in: 3.9.4
NLTK: Default ENFORCE=False Disables All pathsec Security Controls
Fixed in: 3.10.0
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
Fixed in: 3.10.0
NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'
Fixed in: 3.10.3
NLTK: Downloader.download follows hardlinks and overwrites outside-root files
Fixed in: 3.10.3
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
Fixed in: 3.10.3
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
Fixed in: 3.10.3
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
Fixed in: 3.10.3
NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input
Fixed in: 3.10.3
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Fixed in: 3.10.3
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
Fixed in: 3.10.3
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution
Fixed in: 3.10.3
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure
Fixed in: 3.10.3
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
Fixed in: 3.10.1
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
Fixed in: 3.10.0
NLTK network URL validation permits SSRF to RFC 6598 shared-address-space hosts
Fixed in: 3.10.0
NLTK downloader allows cross-package resource and model poisoning
Fixed in: 3.10.0
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
Fixed in: 3.10.0
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
Fixed in: 3.10.0
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
Fixed in: 3.10.0
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
Fixed in: 3.10.0
NLTK vulnerable to Eval Injection via collocations CLI arguments
Fixed in: 3.9.3
NLTK Stanford wrapper classes execute untrusted JAR files without verification
Fixed in: 3.9.4
Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read
Fixed in: 3.10.0
NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
Fixed in: 3.9.4
Unauthenticated remote shutdown in nltk.app.wordnet_app
Fixed in: 3.9.4
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk
Fixed in: 3.9.4
Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS
Fixed in: 3.9.4
NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()
Fixed in: 3.9.3
NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An attacker can supply or replace the JAR file, enabling the execution of arbitrary Java bytecode at import time. This vulnerability can be exploited through methods such as model poisoning, MITM attacks, or dependency poisoning, leading to remote code execution. The issue arises from the direct execution of the JAR file via subprocess with unvalidated classpath input, allowing malicious classes to execute when loaded by the JVM.
Fixed in: 3.9.3
NLTK has a Path Traversal issue
Fixed in: 3.9.3
NLTK has a Zip Slip Vulnerability
Fixed in: 3.9.3
ntlk unsafe deserialization vulnerability
Fixed in: 3.9
NLTK Vulnerable to REDoS
Fixed in: 3.6.6, 2a50a3edc9d35f57ae42a921c621edc160877f4d
Inefficient Regular Expression Complexity in nltk (word_tokenize, sent_tokenize)
Fixed in: 3.6.6, 1405aad979c6b8080dbbc8e0858f89b2e3690341, 3.6.5
NLTK Vulnerable to REDoS
Fixed in: 3.6.4, 277711ab1dec729e626b27aab6fa35ea5efbd7e6
NLTK Vulnerable To Path Traversal
Fixed in: 3.4.5, f59d7ed8df2e0e957f7f247fe218032abdbe9a10