[Git][security-tracker-team/security-tracker][master] Add new batch of nltk issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 22 20:49:30 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d28c0d86 by Salvatore Bonaccorso at 2026-08-22T21:49:02+02:00
Add new batch of nltk issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -45,11 +45,14 @@ CVE-2026-75870 (Punk versions before 0.18 for Perl allow session cookie forgery
 CVE-2026-75866 (Punk::OAuth2::Server versions through 0.03 for Perl issue access token ...)
 	TODO: check
 CVE-2026-71514 (NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in C ...)
-	TODO: check
+	- nltk 3.10.3-1
+	NOTE: Fixed by: https://github.com/nltk/nltk/commit/10d34b3f4fe3fec74b76527a409eb0acbac2e8ab (v3.10.3-rc1)
 CVE-2026-71513 (NLTK before 3.10.3 contains a remote code execution vulnerability in A ...)
-	TODO: check
+	- nltk <unfixed>
+	NOTE: Fixed by: https://github.com/nltk/nltk/commit/c3e37113742a1ebeeb4f2ca58941f320f98805ea (v3.10.3-rc1)
 CVE-2026-70626 (NLTK versions before 3.9.4 contain a symlink escape vulnerability in C ...)
-	TODO: check
+	- nltk 3.10.0-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-r6gq-whwq-mvg9
 CVE-2026-6258
 	REJECTED
 CVE-2026-68769
@@ -73,23 +76,33 @@ CVE-2026-66917 (Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGa
 CVE-2026-66916 (Joomla Extension - joomgalleryfriends.net - Password-Protected Categor ...)
 	NOT-FOR-US: Joomla
 CVE-2026-66393 (NLTK versions before 3.9.4 contain an unbounded recursion vulnerabilit ...)
-	TODO: check
+	- nltk 3.10.0-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-rf74-v2fm-23pw
 CVE-2026-65915 (NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPoint ...)
-	TODO: check
+	- nltk 3.10.0-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-72r2-7mfr-5xr9
 CVE-2026-63312 (NLTK before 3.10.0 contains an arbitrary local file read vulnerability ...)
-	TODO: check
+	- nltk 3.10.0-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-x5ph-mj9p-rfr8
 CVE-2026-63311 (NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side ...)
-	TODO: check
+	- nltk 3.10.0-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-3gqm-fcw5-w839
 CVE-2026-63310 (NLTK before 3.9.3 fails to verify file integrity after downloading pac ...)
-	TODO: check
+	- nltk 3.9.3-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-5wp5-5229-5g6q
 CVE-2026-62388 (NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, ca ...)
-	TODO: check
+	- nltk 3.10.0-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-p3m8-78j2-g5p3
 CVE-2026-62385 (NLTK versions before 3.10.0 contain a path traversal vulnerability in  ...)
-	TODO: check
+	- nltk 3.10.0-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-568f-pv23-39p4
 CVE-2026-62384 (NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in  ...)
-	TODO: check
+	- nltk 3.10.3-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv
+	NOTE: CVE exists because it is possible to bypass the fix for CVE-2026-12074
 CVE-2026-62383 (nltk versions before 3.10.2 contain a symlink-based arbitrary file rea ...)
-	TODO: check
+	- nltk 3.10.3-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-3hhw-38pf-pxj6
 CVE-2026-62382 (PasswordPusher versions v1.45.11 through v2.9.5 contain an improper au ...)
 	TODO: check
 CVE-2026-62381 (luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the nati ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d28c0d86afee1c82a5a85b68a414d7d4aa88b72b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d28c0d86afee1c82a5a85b68a414d7d4aa88b72b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260822/9e26cd26/attachment.htm>


More information about the debian-security-tracker-commits mailing list