nltk vulnerabilities
CVEs whose affected-version data names the nltk package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
34 CVEsRSS
CVE-2026-33230Medium· 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk
▾ Sunlitnltk · nltkEPSS 0.39%via OSV
CVE-2025-14009High· 8.8A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions
A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This a…
▾ Twilightnltk · nltkEPSS 0.95%via NVD
CVE-2024-39705High· 7.5ntlk unsafe deserialization vulnerability
ntlk unsafe deserialization vulnerability
▾ Twilightnltk · nltkEPSS 1.3%via OSV
CVE-2021-43854High· 7.5Inefficient Regular Expression Complexity in nltk (word_tokenize, sent_tokenize)
Inefficient Regular Expression Complexity in nltk (word_tokenize, sent_tokenize)
▾ Twilightnltk · nltkEPSS 2.7%via OSV