Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-12259: NLTK may install tampered packages without checking integrity

CVE-2026-12259 · published 2 months ago
Summary

Version 3.9.4 of the NLTK library can write a downloaded language package to disk before confirming its checksum, so a malicious mirror or proxy could supply altered files that are then installed. This could let attackers place harmful code or data into applications that rely on NLTK. Update NLTK to a newer release that verifies checksums first, or only download packages from trusted sources and verify their integrity manually.

What to do
  • Update nltk to version 3.9.3.
Affected software
Ecosystem VendorProductAffected versions
PyPI – nltk < 3.9.3
Fix: upgrade to 3.9.3
Debian:14 debian nltk All versions
pip – nltk <= 3.9.2
Fix: upgrade to 3.9.3
– nltk nltk/nltk <= latest
Debian:11 debian nltk All versions
Debian:12 debian nltk All versions
Debian:13 debian nltk All versions
Ubuntu:Pro:14.04:LTS canonical nltk All versions
Ubuntu:Pro:16.04:LTS canonical nltk All versions
Ubuntu:Pro:18.04:LTS canonical nltk All versions
Ubuntu:Pro:20.04:LTS canonical nltk All versions
Ubuntu:Pro:22.04:LTS canonical nltk All versions
Ubuntu:Pro:24.04:LTS canonical nltk All versions
Ubuntu:Pro:26.04:LTS canonical nltk All versions
Original advisory text
Duplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to tamper with the package response body for `info.url` through a compromised mirror, malicious proxy, or other source-substitution condition, leading to the installation of attacker-controlled package bytes. The vulnerability can result in malicious corpus or model content being trusted by downstream users or applications.
Fix within
Internet-facing 60 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker partial control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-494Download of Code Without Integrity Check
Timeline
Published3 Aug 2026
Updated7 Oct 2026
First seen3 Aug 2026
Track software like this
Free during beta