Nltk
Vendor:
First CVE: Aug 22, 2019 · Active for 6 years
14
Total CVEs
More Total CVEs than 92% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nltk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2019
6 years ago
Most Recent CVE
Jul 4, 2026
24 days ago
CVE Severity & Scoring
Nltk14 CVEs
86%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.1%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (78.6%)
Unknown0 (0.0%)
Required3 (21.4%)
Privileges Required
Low1 (7.1%)
High0 (0.0%)
None13 (92.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14009HIGH A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() with | Feb 18, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-0848CRITICAL NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar f | Mar 5, 2026 | 10.0 | 36 | NO | NO |
CVE-2026-12252HIGH In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependen | Jul 4, 2026 | 7.8 | 35 | NO | NO |
CVE-2026-12243HIGH NLTK version 3.9.4 is vulnerable to a path traversal attack due to an incomplete fix for GitHub Issue #3504. The `_UNSAFE_NO_PROTOCOL_RE` regex in `nltk/data.py` checks for literal | Jun 30, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-54293HIGH NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10 | Jun 22, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-33236HIGH NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3 | Mar 20, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-0847HIGH A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCor | Mar 4, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-0846HIGH A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function di | Mar 9, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-33231HIGH NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3 | Mar 20, 2026 | 7.5 | 28 | NO | NO |
CVE-2019-14751HIGH NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is | Aug 22, 2019 | 7.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Nltk
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.9.4 | 1 | 7.5 | 0.6% | 0 | 0 |
| 3.9.2 | 1 | 7.5 | 0.4% | 0 | 0 |