Packages
- nltk - Natural Language Toolkit
Details
It was discovered that NLTK incorrectly validated file paths when
opening files using the nltk.util module. An attacker could possibly
use this issue to obtain sensitive information. (CVE-2026-0846)
It was discovered that NLTK incorrectly validated file paths in
multiple CorpusReader classes. An attacker could possibly use
this issue to obtain sensitive information. (CVE-2026-0847)
It was discovered that NLTK did not properly validate external
Java archive files loaded by StanfordSegmenter. An attacker
could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu
22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-0848)
It was discovered that NLTK's WordNet browser application
incorrectly handled user-supplied input. An attacker...
It was discovered that NLTK incorrectly validated file paths when
opening files using the nltk.util module. An attacker could possibly
use this issue to obtain sensitive information. (CVE-2026-0846)
It was discovered that NLTK incorrectly validated file paths in
multiple CorpusReader classes. An attacker could possibly use
this issue to obtain sensitive information. (CVE-2026-0847)
It was discovered that NLTK did not properly validate external
Java archive files loaded by StanfordSegmenter. An attacker
could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu
22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-0848)
It was discovered that NLTK's WordNet browser application
incorrectly handled user-supplied input. An attacker could
possibly use this issue to perform a cross-site scripting
attack. (CVE-2026-33230)
It was discovered that NLTK's WordNet browser application did
not restrict access to the shutdown endpoint. A remote attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-33231)
It was discovered that NLTK's downloader did not validate path
attributes in remote XML index files. An attacker could possibly
use this issue to create or overwrite arbitrary files.
(CVE-2026-33236)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 26.04 LTS resolute | python3-nltk – 3.9.2-1ubuntu0.1~esm2 | ||
| 24.04 LTS noble | python3-nltk – 3.8.1-1ubuntu0.1~esm2 | ||
| 22.04 LTS jammy | python3-nltk – 3.7-1ubuntu0.1~esm2 | ||
| 20.04 LTS focal | python3-nltk – 3.4.5-2ubuntu0.1~esm4 | ||
| 18.04 LTS bionic | python-nltk – 3.2.5-1ubuntu0.1+esm4 | ||
| python3-nltk – 3.2.5-1ubuntu0.1+esm4 | |||
| 16.04 LTS xenial | python-nltk – 3.1-1ubuntu0.1+esm4 | ||
| python3-nltk – 3.1-1ubuntu0.1+esm4 | |||
| 14.04 LTS trusty | python-nltk – 2.0~b9-0ubuntu4.1~esm6 | ||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.