Direct Vulnerabilities

Known vulnerabilities in the nltk package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Link Following

<3.10.3-1
  • H
Algorithmic Complexity

<3.10.3-1
  • H
External Control of File Name or Path

*
  • L
Resource Exhaustion

<3.10.3-1
  • L
Resource Exhaustion

<3.10.3-1
  • M
Uncontrolled Recursion

<3.10.3-1
  • H
Inefficient Regular Expression Complexity

<3.10.0-1
  • L
CVE-2026-80206

<3.10.3-1
  • H
External Control of File Name or Path

<3.10.3-1
  • C
Arbitrary Argument Injection

<3.10.3-1
  • C
Deserialization of Untrusted Data

<3.10.3-1
  • M
Directory Traversal

<3.10.3-1
  • H
Untrusted Search Path

<3.10.3-1
  • H
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<3.10.3-1
  • C
Deserialization of Untrusted Data

<3.10.0-1
  • H
Server-Side Request Forgery (SSRF)

<3.10.3-1
  • H
Insecure Default Initialization of Resource

<3.10.0-1
  • M
Download of Code Without Integrity Check

<3.9.3-1
  • M
Directory Traversal

<3.10.3-1
  • H
External Control of File Name or Path

<3.10.0-1
  • M
Improper Access Control

<3.10.0-1
  • M
Server-Side Request Forgery (SSRF)

<3.10.0-1
  • H
Uncontrolled Recursion

<3.10.0-1
  • H
Deserialization of Untrusted Data

<3.10.3-1
  • L
Directory Traversal

<3.10.3-1
  • H
Directory Traversal

<3.10.0-1
  • M
Link Following

<3.10.0-1
  • H
Directory Traversal

<3.10.3-1
  • H
Inefficient Regular Expression Complexity

<3.10.3-1
  • L
CVE-2026-12841

<3.10.3-1
  • L
CVE-2026-12876

*
  • L
CVE-2026-12072

<3.10.0-1
  • L
CVE-2026-12061

<3.10.0-1
  • L
CVE-2026-12074

<3.10.0-1
  • M
Improper Access Control

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Download of Code Without Integrity Check

*
  • H
Eval Injection

<3.9.3-1
  • L
Arbitrary Code Injection

<3.10.3-1
  • L
Directory Traversal

<3.10.0-1
  • L
Missing Authentication for Critical Function

*
  • L
Cross-site Scripting (XSS)

<3.10.0-1
  • L
Missing Authentication for Critical Function

<3.10.0-1
  • L
Directory Traversal

<3.10.0-1
  • H
Directory Traversal

<3.9.3-1
  • L
CVE-2026-0848

<3.9.3-1
  • H
Directory Traversal

<3.9.3-1
  • L
Arbitrary Code Injection

<3.9.3-1
  • L
Directory Traversal

<3.4.5-1
  • H
Inefficient Regular Expression Complexity

<3.6.7-1
  • H
Insufficient Comparison

<3.6.5-1
  • L
CVE-2024-39705

<3.9.1-1
  • H
Resource Exhaustion

<3.6.7-1