CVE-2026-78682High· 7.5▾ TwilightA flaw was found in NLTK. When an HTTP proxy is configured, a server-side request forgery (SSRF) vulnerability exists in the `nltk.pathsec.urlopen` function. An attacker can exploit this by providing a seemingly valid public URL, which the…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
— → 7.5
none → high
7.5 → —
high → none
— → 7.5
none → high
Last analysed / modified upstream
A flaw was found in NLTK. When an HTTP proxy is configured, a server-side request forgery (SSRF) vulnerability exists in the nltk.pathsec.urlopen function. An attacker can exploit this by providing a seemingly valid public URL, which the proxy then forwards to an internal service without proper re-validation. This could lead to the disclosure of internal network resources, the loading of malicious downloader indexes, and the installation of attacker-controlled package content.
nltk: NLTK: Server-Side Request Forgery via HTTP Proxy Configuration — rated Important by Red Hat. Released 2026-08-25, updated 2026-09-15.
Affected:
No fix planned:
Will not fix
Workarounds / mitigations:
Affected packages:
nltk < 3.10.3Patched in:
nltk 3.10.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81725Medium· 5.9nltk: NLTK: Regular Expression Denial of Service via malformed TEI blocks (CVE-2026-81725)
CVE-2026-79674High· 7.5nltk: NLTK: Information disclosure via path traversal in corpus-reader constructors (CVE-2026-79674)
CVE-2026-79675High· 8.1nltk: NLTK before 3.10.3 JVM Argument Injection via Per-Call Options (CVE-2026-79675)
CVE-2026-80205High· 7.5nltk: NLTK: Denial of Service via unvalidated regular expressions (CVE-2026-80205)
CVE-2026-81724High· 7.5nltk: NLTK: Denial of Service via Uncontrolled Recursion (CVE-2026-81724)
CVE-2026-81727High· 7.1nltk: NLTK: Filesystem containment bypass allows local file overwrite (CVE-2026-81727)