Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33236

31
FAUCET Score

CVE-2026-33236 affects NLTK (Natural Language Toolkit) versions 3.9.3 and prior, stemming from a lack of validation in its downloader when processing remote XML index files. This high-severity vulnerability (CVSS 8.1) allows unauthenticated remote attackers to achieve arbitrary file and directory creation or overwrite through path traversal sequences, requiring user interaction. Attackers can exploit this by controlling a remote XML index server to provide malicious values. While there is no known active exploitation, public exploit code, or CISA KEV listing, a patch is available in commit 89fe2ec2c6bae6e2e7a46dad65cc34231976ed8a.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.9.3CPE matchmatch criteria
cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.57%
Probability of exploitation in next 30 days
EPSS Percentile
44.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0057 is in the 46th percentile among its peer group of 14,852 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

github_advisorypatch availablevia nvd_reference
View patch
ubuntupatch availablevia ubuntu_usn
Product: nltk (focal)Fixed in: 3.4.5-2ubuntu0.1~esm4
ubuntupatch availablevia ubuntu_usn
Product: nltk (jammy)Fixed in: 3.7-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: nltk (noble)Fixed in: 3.8.1-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: nltk (resolute)Fixed in: 3.9.2-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: nltk (bionic)Fixed in: 3.2.5-1ubuntu0.1+esm4
ubuntupatch availablevia ubuntu_usn
Product: nltk (xenial)Fixed in: 3.1-1ubuntu0.1+esm4
ubuntupatch availablevia ubuntu_usn
Product: nltk (trusty)Fixed in: 2.0~b9-0ubuntu4.1~esm6
golangvendor investigatingvia llm_extracted
hikvisionvendor investigatingvia llm_extracted

Vendor Advisories (4)

ubuntuUSN-8302-1

NLTK vulnerabilities

May 25, 2026
hikvisionllm-hikvision-48a9669be26aab0fHIGH

NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite

Mar 19, 2026
pipGHSA-469j-vmhf-r6v7high

NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite

Mar 19, 2026
golangllm-golang-95886722a243ff42HIGH

NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite

Mar 19, 2026

References

access.redhat.com / errata/RHSA-2026:10184
access.redhat.com / errata/RHSA-2026:19712
access.redhat.com / errata/RHSA-2026:37275
access.redhat.com / errata/RHSA-2026:42644
access.redhat.com / security/cve/CVE-2026-33236
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-33236.json
github.com / nltk/nltk/commit/89fe2ec2c6bae6e2e7a46dad65cc34231976ed8a
Patch
github.com / nltk/nltk/security/advisories/GHSA-469j-vmhf-r6v7
ExploitVendor Advisory