PT-2026-79561 · Pypi · Nltk

·

CVE-2026-63310

·

Published

2026-08-22

·

Updated

2026-09-08

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NLTK versions prior to 3.9.3
Description The downloader module fails to verify file integrity after downloading packages and before extraction. This allows attackers to use man-in-the-middle attacks or DNS poisoning to inject malicious package contents, which are then extracted without validation.
Recommendations Update to version 3.9.3 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63310
GHSA-5WP5-5229-5G6Q
GHSA-GF32-CMJH-8M9V
PYSEC-2026-3729

Affected Products

Nltk