Apache-2.0
All Versions
Vulnerabilities (Public)
Known vulnerabilities and security issues detected in the extension's dependencies and code.
| Vulnerability ID | Advisory | Affected Versions | |||
|---|---|---|---|---|---|
| CVE-2026-12075 | nltk – Server-Side Request Forgery (SSRF) | High | – | – | <= 3.9.4 |
| CVE-2026-12061 | nltk – Regular Expression Denial of Service (ReDoS) | High | – | – | <= 3.9.4 |
| CVE-2026-12072 | nltk – Path Traversal | High | – | – | <= 3.9.4 |
| CVE-2026-12074 | nltk – Path Traversal | High | – | – | <= 3.9.4 |
| CVE-2026-54293 | nltk – Path Traversal | High | – | – | <= 3.9.4 |
| CVE-2026-33236 | Affected versions of the nltk package are vulnerable to Arbitrary File Overwrite due to improper validation of path components from remote XML index files. The vulnerability exists in nltk/downloader.… | High | – | – | <=3.9.2 |
| CVE-2026-33231 | Affected versions of the nltk package are vulnerable to Denial of Service (DoS) due to missing authentication on a shutdown function in the WordNet Browser HTTP server. In nltk.app.wordnet_app, HTTPSe… | High | – | – | <=3.9.3 |
| CVE-2026-0846 | NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring() | High | – | – | < 3.9.3 |
| CVE-2026-33230 | Affected versions of the nltk package are vulnerable to Cross-site Scripting (XSS) due to improper output encoding of user-controlled input. In nltk.app.wordnet_app, requests to the lookup_... route a… | Medium | – | – | <=3.9.3 |
| SFTY-20260320-58622 | nltk – Uncontrolled Recursion | Medium | – | – | <=3.9.3 |
Page 1
Safety Discovered Vulnerabilities
Additional security issues found by Safety, exclusive to our platform.

