Direct Vulnerabilities

Known vulnerabilities in the nltk package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
External Control of File Name or Path

*
  • L
Resource Exhaustion

*
  • L
Algorithmic Complexity

*
  • L
Resource Exhaustion

*
  • L
Uncontrolled Recursion

*
  • L
Link Following

*
  • L
CVE-2026-80206

*
  • L
Inefficient Regular Expression Complexity

*
  • L
Directory Traversal

*
  • L
Deserialization of Untrusted Data

*
  • L
Arbitrary Argument Injection

*
  • L
External Control of File Name or Path

*
  • L
Untrusted Search Path

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Deserialization of Untrusted Data

*
  • L
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • L
Directory Traversal

*
  • L
Improper Access Control

*
  • L
Link Following

*
  • L
Directory Traversal

*
  • L
Directory Traversal

*
  • L
Directory Traversal

*
  • L
Uncontrolled Recursion

*
  • L
Insecure Default Initialization of Resource

*
  • L
Deserialization of Untrusted Data

*
  • L
External Control of File Name or Path

*
  • L
Download of Code Without Integrity Check

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Inefficient Regular Expression Complexity

*
  • L
CVE-2026-12841

*
  • L
CVE-2026-12876

*
  • L
CVE-2026-12074

*
  • L
CVE-2026-12072

*
  • L
CVE-2026-12061

*
  • L
Improper Access Control

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Download of Code Without Integrity Check

*
  • L
Eval Injection

*
  • L
Arbitrary Code Injection

*
  • L
Directory Traversal

*
  • L
Missing Authentication for Critical Function

*
  • L
Directory Traversal

*
  • L
Cross-site Scripting (XSS)

*
  • L
Missing Authentication for Critical Function

*
  • L
Directory Traversal

*
  • L
CVE-2026-0848

*
  • L
Directory Traversal

*
  • L
Arbitrary Code Injection

*
  • L
CVE-2024-39705

<3.9.1-1
  • H
Inefficient Regular Expression Complexity

<3.6.7-1
  • H
Resource Exhaustion

<3.6.7-1
  • H
Insufficient Comparison

<3.6.5-1
  • L
Directory Traversal

<3.4.5-1