CVE-2026-12259
Improper Input Validation in nltk/nltk
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to tamper with the package response body for `info.url` through a compromised mirror, malicious proxy, or other source-substitution condition, leading to the installation of attacker-controlled package bytes. The vulnerability can result in malicious corpus or model content being trusted by downstream users or applications.
| CWE | CWE-494 |
| Vendor | nltk |
| Product | nltk/nltk |
| Published | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for nltk nltk/nltk
Be the first to know when new medium vulnerabilities affecting nltk nltk/nltk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Versions
nltk / nltk/nltk
unspecified โค latest