CVE Tools

Nltk

46 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Nltk, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Nltk CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Nltk CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-021
2026-037
2026-040
2026-050
2026-061
2026-072
2026-0830
2026-090

Severity

How the 46 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical511%
  • High2658%
  • Medium1022%
  • Low49%

Latest CVEs

The 15 most recently published vulnerabilities affecting Nltk.

  1. CVE-2026-81727NLTK before 3.10.3 Hardlink File Overwrite via downloader7.1
  2. CVE-2026-81725NLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReader3.7
  3. CVE-2026-81726NLTK through 3.10.3 Path Traversal via Model-Artifact APIs7.0
  4. CVE-2026-81724NLTK before 3.10.3 Denial of Service via Uncontrolled Recursion5.3
  5. CVE-2026-81723NLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusView3.7
  6. CVE-2026-81722nltk PorterStemmer before 3.10.3 Quadratic-time DoS7.5
  7. CVE-2026-80206NLTK 3.10.2 Regular Expression Denial of Service via tgrep5.9
  8. CVE-2026-80205NLTK before 3.10.0 ReDoS via Text.findall() unvalidated regex7.5
  9. CVE-2026-79676NLTK before 3.10.3 Path Traversal via Symlink Bypass5.9
  10. CVE-2026-79675NLTK before 3.10.3 JVM Argument Injection via Per-Call Options9.8
  11. CVE-2026-79674NLTK 3.10.2 Path Traversal via corpus-reader constructors8.2
  12. CVE-2026-79657NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization9.8
  13. CVE-2026-78683NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization9.6
  14. CVE-2026-78682NLTK before 3.10.3 SSRF Protection Bypass via Proxy7.5
  15. CVE-2026-78681NLTK before 3.10.3 Entity Expansion DoS via ElementTree7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store