stanza vulnerabilities
CVEs whose affected-version data names the stanza package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-59974High· 7.8PoCStanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages
Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes downloaded model and resource …
▾ Midnightstanfordnlp · stanzaEPSS 0.47%via NVD
CVE-2026-54499High· 7.5Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
▾ Twilightstanza · stanzaEPSS 0.52%via GHSA