Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-71513: NLTK can run malicious code when parsing models
CVE-2026-71513 · published 1 month ago
Summary
Versions of the Natural Language Toolkit (NLTK) up to 3.10.2 allow specially crafted language models to execute any code on the system during parsing. This could let an attacker take control of the server or workstation running the affected NLTK version. Update NLTK to version 3.10.3 or later, or stop using untrusted models, to eliminate the risk.
What to do
- Update nltk team nltk to version 3.10.3.
- Update debian nltk to version 3.10.3-1.
- Update nltk to version 3.10.3.
- Update nltk nltk to version 3.10.3 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | nltk team | nltk |
>= 3.10.0, < 3.10.3 Fix: upgrade to 3.10.3
|
| – | nltk | nltk | < 3.10.3 |
| Debian:11 | debian | nltk | All versions |
| Debian:12 | debian | nltk | All versions |
| Debian:13 | debian | nltk | All versions |
| Debian:14 | debian | nltk |
< 3.10.3-1 Fix: upgrade to 3.10.3-1
|
| Ubuntu:Pro:14.04:LTS | canonical | nltk | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | nltk | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | nltk | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | nltk | All versions |
| Ubuntu:Pro:22.04:LTS | canonical | nltk | All versions |
| Ubuntu:Pro:24.04:LTS | canonical | nltk | All versions |
| Ubuntu:Pro:26.04:LTS | canonical | nltk | All versions |
| PyPI | – | nltk |
>= 3.10.0, < 3.10.3 Fix: upgrade to 3.10.3
|
Original advisory text
NLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name Bypass
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the model through allowlisted_pickle_load.
References
- https://github.com/cveproject/cvelistv5/tree/main/cves/2026/71xxx/cve-2026-71513... Third Party Advisory
- https://nvd.nist.gov/vuln/detail/cve-2026-71513 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-71513 Third Party Advisory
- https://security-tracker.debian.org/tracker/cve-2026-71513 Third Party Advisory
- https://github.com/nltk/nltk/blob/v3.10.2/nltk/picklesec.py#l119-l124 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-71513 Third Party Advisory
- https://github.com/nltk/nltk/blob/v3.10.2/nltk/picklesec.py#L119-L124 Third Party Advisory
- https://github.com/nltk/nltk/commit/c3e37113742a1ebeeb4f2ca58941f320f98805ea Patch
- https://www.vulncheck.com/advisories/nltk-through-remote-code-execution-via-allo... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-71513 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71513... Vendor Advisory
- https://github.com/nltk/nltk Product
- https://pypi.org/project/nltk Product
- https://security-tracker.debian.org/tracker/CVE-2026-71513 Vendor Advisory
- https://github.com/advisories/GHSA-5gh2-94qg-qppq
Severity
9.9
Critical
CVSS 4.0: 9.9 (OSV)
CVSS 3.1: 8.8 (OSV)
CVSS 3.1: 8.8 (NVD)
CVSS 4.0: 8.7 (NVD)
Exploitation
EPSS 1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published22 Aug 2026
Updated27 Sep 2026
First seen22 Aug 2026
Sources
CVE-2026-71513 · NVD
CVE-2026-71513 · MITRE
DEBIAN-CVE-2026-71513 · OSV
UBUNTU-CVE-2026-71513 · OSV
GHSA-5gh2-94qg-qppq · GHSA
GHSA-5gh2-94qg-qppq · OSV
PYSEC-2026-3867 · OSV
CVE-2026-71513 · OSV
Track software like this
Free during beta