CVE-2026-79675High· 8.1▾ TwilightA flaw was found in NLTK. When processing untrusted input for its `per-call options` parameter in the `java()` function, NLTK fails to validate Java Virtual Machine (JVM) options. A remote attacker could exploit this by injecting dangerous…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
0.4% → 0.4%
8.1 → 9.8
high → critical
9.8 → 8.1
critical → high
8.1 → 9.8
high → critical
9.8 → 8.1
critical → high
8.1 → 9.8
high → critical
Last analysed / modified upstream
9.8 → 8.1
critical → high
A flaw was found in NLTK. When processing untrusted input for its per-call options parameter in the java() function, NLTK fails to validate Java Virtual Machine (JVM) options. A remote attacker could exploit this by injecting dangerous JVM flags, such as -agentpath or -javaagent, to achieve arbitrary code execution. Successful exploitation requires specific conditions, indicating a higher attack complexity.
nltk: NLTK before 3.10.3 JVM Argument Injection via Per-Call Options — rated Important by Red Hat. Released 2026-08-25, updated 2026-09-15.
Affected:
No fix planned:
Not affected:
Will not fix
Workarounds / mitigations:
Affected packages:
nltk < 3.10.3Patched in:
nltk 3.10.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81725Medium· 5.9nltk: NLTK: Regular Expression Denial of Service via malformed TEI blocks (CVE-2026-81725)
CVE-2026-79674High· 7.5nltk: NLTK: Information disclosure via path traversal in corpus-reader constructors (CVE-2026-79674)
CVE-2026-78682High· 7.5nltk: NLTK: Server-Side Request Forgery via HTTP Proxy Configuration (CVE-2026-78682)
CVE-2026-78679Medium· 6.5GitPython: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679)
CVE-2026-78678Medium· 6.5gitpython: GitPython: Arbitrary file read via Repo.blame() (CVE-2026-78678)
CVE-2026-78676Critical· 9.8gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection (CVE-2026-78676)