---
id: CVE-2026-12372
title: >-
  A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk
  versions 3.9.4 and the current develop branch
summary: >-
  A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk
  versions 3.9.4 and the current develop branch. The
  `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by
  rejecting internal network addresses, f…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-918
published: '2026-08-09'
updated: '2026-08-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12372'
references:
  - url: 'https://huntr.com/bounties/2911b643-571c-42e4-b0c2-9a1fa6f491db'
    label: security@huntr.dev
tags:
  - nvd
  - osv
  - pip
ingestedAt: '2026-08-10T04:38:56.478Z'
epss: 0.0031
epssPercentile: 0.21239
aliases:
  - PYSEC-2026-3955
ecosystem: pip
vendor: nltk
product: nltk
affected:
  - nltk <= 3.9.4
---

## Overview

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared address space (`100.64.0.0/10`). This occurs because Python's `ipaddress` module does not classify such addresses as `is_private` or `is_global`, and the current guard only checks `is_private` and a few explicit categories. An attacker who can influence a URL passed to NLTK's network-loading helpers can exploit this vulnerability to make a strict-mode application send requests to shared-address-space hosts, potentially exposing non-public infrastructure reachable from the application host. The impact is limited to SSRF-style confidentiality exposure, with no code execution claimed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-12372)

Affected packages:

- `nltk <= 3.9.4`

Source: https://osv.dev/vulnerability/PYSEC-2026-3955
