NLTK is a prominent Python natural-language processing library and toolkit widely embedded in machine-learning pipelines, text-analysis systems, and educational platforms, creating a supply-chain impact that amplifies the significance of its small product footprint. Vulnerabilities affecting the library skew toward serious outcomes and cluster around input-handling weaknesses including path-traversal flaws, inefficient regular-expression patterns, code-injection vectors, and improper input validation that arise from processing untrusted text data. Defenders should review downstream applications and data-processing workflows that depend on this library, particularly where it handles user-supplied or web-sourced inputs; live severity and current exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nltk over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14009HIGH A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() with | Feb 18, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-0848CRITICAL NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar f | Mar 5, 2026 | 10.0 | 36 | NO | NO |
CVE-2026-12252HIGH In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependen | Jul 4, 2026 | 7.8 | 35 | NO | NO |
CVE-2026-12243HIGH NLTK version 3.9.4 is vulnerable to a path traversal attack due to an incomplete fix for GitHub Issue #3504. The `_UNSAFE_NO_PROTOCOL_RE` regex in `nltk/data.py` checks for literal | Jun 30, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-54293HIGH NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10 | Jun 22, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-33236HIGH NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3 | Mar 20, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-0847HIGH A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCor | Mar 4, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-0846HIGH A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function di | Mar 9, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-33231HIGH NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3 | Mar 20, 2026 | 7.5 | 28 | NO | NO |
CVE-2019-14751HIGH NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is | Aug 22, 2019 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nltk.
Media articles that mention a CVE ID that affects a product developed by Nltk — matched by CVE ID, not by vendor name.