Vendor
critical
advisory
Denial of Service Vulnerability in nltk PorterStemmer
4 TTPs 1 CVEAn algorithmic complexity vulnerability in the nltk PorterStemmer module allows unauthenticated attackers to cause high CPU usage via specially crafted inputs.
nltk +3
vulnerability
rce
python
java
sandbox-bypass
path-traversal
library-vulnerability
sandbox-escape
+1
4t
1c
updated
high
advisory
Remote Code Execution in NLTK AllowlistUnpickler
1 rule 4 TTPs 1 CVENLTK versions prior to 3.10.3 are vulnerable to remote code execution due to improper validation of dotted names during the unpickling of transition-parser models.
nltk +2
1r
4t
1c
updated
high
advisory
CVE-2025-71408 NLTK Eval Injection Vulnerability
1 TTP 1 CVEAn eval injection vulnerability exists in the nltk.collocations module of NLTK (Natural Language Toolkit) versions prior to 3.9.3, allowing an attacker to exploit this by controlling command-line arguments passed to collocations.py, which are then unsafely passed to eval() enabling remote code execution on the affected system.
NLTK
eval-injection
remote-code-execution
python
1t
1c