{"id":"CVE-2026-12372","title":"A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch","summary":"A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, f…","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-918"],"published":"2026-08-09","updated":"2026-08-09","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12372","references":[{"url":"https://huntr.com/bounties/2911b643-571c-42e4-b0c2-9a1fa6f491db","label":"security@huntr.dev"}],"tags":["nvd","osv","pip"],"ingestedAt":"2026-08-10T04:38:56.478Z","epss":0.0026,"epssPercentile":0.17999,"aliases":["PYSEC-2026-3955"],"ecosystem":"pip","vendor":"nltk","product":"nltk","affected":["nltk <= 3.9.4"],"slug":"CVE-2026-12372","body":"## Overview\n\nA Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared address space (`100.64.0.0/10`). This occurs because Python's `ipaddress` module does not classify such addresses as `is_private` or `is_global`, and the current guard only checks `is_private` and a few explicit categories. An attacker who can influence a URL passed to NLTK's network-loading helpers can exploit this vulnerability to make a strict-mode application send requests to shared-address-space hosts, potentially exposing non-public infrastructure reachable from the application host. The impact is limited to SSRF-style confidentiality exposure, with no code execution claimed.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-12372)\n\nAffected packages:\n\n- `nltk <= 3.9.4`\n\nSource: https://osv.dev/vulnerability/PYSEC-2026-3955","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}