Direct Vulnerabilities

Known vulnerabilities in the nltk package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
External Control of File Name or Path

*
  • H
Algorithmic Complexity

<3.10.3-1
  • L
Resource Exhaustion

<3.10.3-1
  • H
Link Following

<3.10.3-1
  • L
Resource Exhaustion

<3.10.3-1
  • M
Uncontrolled Recursion

<3.10.3-1
  • L
CVE-2026-80206

<3.10.3-1
  • H
Inefficient Regular Expression Complexity

<3.10.0-1
  • C
Arbitrary Argument Injection

<3.10.3-1
  • M
Directory Traversal

<3.10.3-1
  • C
Deserialization of Untrusted Data

<3.10.3-1
  • H
External Control of File Name or Path

<3.10.3-1
  • H
Untrusted Search Path

<3.10.3-1
  • H
Server-Side Request Forgery (SSRF)

<3.10.3-1
  • H
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<3.10.3-1
  • C
Deserialization of Untrusted Data

<3.10.0-1
  • H
Insecure Default Initialization of Resource

<3.10.0-1
  • M
Improper Access Control

<3.10.0-1
  • L
Directory Traversal

<3.10.3-1
  • H
Uncontrolled Recursion

<3.10.0-1
  • M
Directory Traversal

<3.10.3-1
  • M
Server-Side Request Forgery (SSRF)

<3.10.0-1
  • M
Link Following

<3.10.0-1
  • H
Directory Traversal

<3.10.0-1
  • H
External Control of File Name or Path

<3.10.0-1
  • H
Deserialization of Untrusted Data

<3.10.3-1
  • H
Directory Traversal

<3.10.3-1
  • M
Download of Code Without Integrity Check

<3.9.3-1
  • H
Inefficient Regular Expression Complexity

<3.10.3-1
  • L
CVE-2026-12841

<3.10.3-1
  • L
CVE-2026-12876

*
  • L
CVE-2026-12072

<3.10.0-1
  • L
CVE-2026-12074

<3.10.0-1
  • L
CVE-2026-12061

<3.10.0-1
  • L
Improper Access Control

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Download of Code Without Integrity Check

*
  • H
Eval Injection

<3.9.3-1
  • L
Arbitrary Code Injection

<3.10.3-1
  • L
Directory Traversal

<3.10.0-1
  • L
Missing Authentication for Critical Function

*
  • L
Cross-site Scripting (XSS)

<3.10.0-1
  • L
Missing Authentication for Critical Function

<3.10.0-1
  • L
Directory Traversal

<3.10.0-1
  • H
Directory Traversal

<3.9.3-1
  • L
CVE-2026-0848

<3.9.3-1
  • H
Directory Traversal

<3.9.3-1
  • L
Arbitrary Code Injection

<3.9.3-1
  • L
CVE-2024-39705

<3.9.1-1
  • H
Inefficient Regular Expression Complexity

<3.6.7-1
  • H
Resource Exhaustion

<3.6.7-1
  • H
Insufficient Comparison

<3.6.5-1
  • L
Directory Traversal

<3.4.5-1