Direct Vulnerabilities

Known vulnerabilities in the nltk package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Link Following

*
  • H
External Control of File Name or Path

*
  • L
Resource Exhaustion

*
  • M
Uncontrolled Recursion

*
  • L
Resource Exhaustion

*
  • H
Algorithmic Complexity

*
  • L
CVE-2026-80206

*
  • H
Inefficient Regular Expression Complexity

*
  • M
Directory Traversal

*
  • C
Arbitrary Argument Injection

*
  • H
External Control of File Name or Path

*
  • C
Deserialization of Untrusted Data

*
  • C
Deserialization of Untrusted Data

*
  • H
Server-Side Request Forgery (SSRF)

*
  • H
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • H
Untrusted Search Path

*
  • L
Directory Traversal

*
  • H
Deserialization of Untrusted Data

*
  • M
Link Following

*
  • H
Uncontrolled Recursion

*
  • M
Improper Access Control

*
  • H
Directory Traversal

*
  • M
Server-Side Request Forgery (SSRF)

*
  • M
Download of Code Without Integrity Check

*
  • H
Insecure Default Initialization of Resource

*
  • H
External Control of File Name or Path

*
  • H
Directory Traversal

*
  • M
Directory Traversal

*
  • H
Inefficient Regular Expression Complexity

*
  • L
CVE-2026-12876

*
  • L
CVE-2026-12841

*
  • L
CVE-2026-12074

*
  • L
CVE-2026-12072

*
  • L
CVE-2026-12061

*
  • M
Improper Access Control

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Download of Code Without Integrity Check

*
  • L
Directory Traversal

*
  • L
Directory Traversal

*
  • L
Missing Authentication for Critical Function

*
  • L
Cross-site Scripting (XSS)

*
  • L
Arbitrary Code Injection

*
  • L
Directory Traversal

*
  • L
Missing Authentication for Critical Function

*
  • H
Eval Injection

*
  • L
Arbitrary Code Injection

*
  • L
CVE-2024-39705

<3.9.1-1
  • H
Resource Exhaustion

<3.6.7-1
  • H
Directory Traversal

<3.4.5-1
  • L
CVE-2026-0848

*
  • H
Directory Traversal

*
  • H
Directory Traversal

*
  • H
Inefficient Regular Expression Complexity

<3.6.7-1
  • H
Insufficient Comparison

<3.6.5-1