Direct Vulnerabilities

Known vulnerabilities in the nltk package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Uncontrolled Recursion

*
  • L
Resource Exhaustion

*
  • L
Link Following

*
  • L
External Control of File Name or Path

*
  • L
Algorithmic Complexity

*
  • L
Resource Exhaustion

*
  • L
Inefficient Regular Expression Complexity

*
  • L
CVE-2026-80206

*
  • L
Arbitrary Argument Injection

*
  • L
Deserialization of Untrusted Data

*
  • L
Directory Traversal

*
  • L
External Control of File Name or Path

*
  • L
Deserialization of Untrusted Data

*
  • L
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Untrusted Search Path

*
  • L
Link Following

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Uncontrolled Recursion

*
  • L
Deserialization of Untrusted Data

*
  • L
Directory Traversal

*
  • L
Directory Traversal

*
  • L
Improper Access Control

*
  • L
Directory Traversal

*
  • L
External Control of File Name or Path

*
  • L
Insecure Default Initialization of Resource

*
  • M
Download of Code Without Integrity Check

*
  • L
Directory Traversal

*
  • L
Inefficient Regular Expression Complexity

*
  • L
CVE-2026-12876

*
  • L
CVE-2026-12841

*
  • L
CVE-2026-12072

*
  • L
CVE-2026-12074

*
  • L
CVE-2026-12061

*
  • L
Improper Access Control

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Download of Code Without Integrity Check

*
  • L
Eval Injection

*
  • L
Arbitrary Code Injection

*
  • L
Directory Traversal

*
  • L
Missing Authentication for Critical Function

*
  • L
Missing Authentication for Critical Function

*
  • L
Directory Traversal

*
  • L
Cross-site Scripting (XSS)

*
  • L
Directory Traversal

*
  • L
CVE-2026-0848

*
  • L
Directory Traversal

*
  • L
Arbitrary Code Injection

*
  • L
CVE-2024-39705

*
  • H
Inefficient Regular Expression Complexity

<3.6.7-1
  • H
Resource Exhaustion

<3.6.7-1
  • H
Insufficient Comparison

<3.6.5-1
  • L
Directory Traversal

<3.4.5-1