Home/Product/nltk
Product

nltk

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-33236
<= 3.9.3
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and develop
8.1HIGH
CVE-2026-33231
<= 3.9.3
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and develop
7.5HIGH
CVE-2026-33230
<= 3.9.3
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and develop
6.1MEDIUM
CVE-2026-0846
all versions
A vulnerability in the filestring() function of the nltk.util module in nltk version 3.9.2 allows arbitrary file read due to i
7.5HIGH
CVE-2026-0848
<= 3.9.2
NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module.
10.0CRITICAL
CVE-2026-0847
<= 3.9.2
A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader
7.5HIGH
CVE-2025-14009
< 3.9.3
A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in
10.0CRITICAL
CVE-2021-3842
< 3.6.6
nltk is vulnerable to Inefficient Regular Expression Complexity
7.5HIGH
CVE-2021-43854
< 3.6.5
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and develop
7.5HIGH
CVE-2021-3828
<= 3.6.3
nltk is vulnerable to Inefficient Regular Expression Complexity
7.5HIGH
CVE-2019-14751
< 3.4.5
NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot do
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin