[Git][security-tracker-team/security-tracker][master] Add new nltk issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 25 08:31:59 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c0142938 by Salvatore Bonaccorso at 2026-08-25T09:31:35+02:00
Add new nltk issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,13 +3,17 @@ CVE-2026-7455 (A maliciously crafted FLT file, when parsed through Autodesk 3ds
CVE-2026-78685 (Medical Practice Management System developed by Le-yan has a Remote Co ...)
TODO: check
CVE-2026-78683 (NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pick ...)
- TODO: check
+ - nltk 3.10.0-1
+ NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-rhp5-r9x4-f5g2
CVE-2026-78682 (NLTK before 3.10.3 contains a server-side request forgery vulnerabilit ...)
- TODO: check
+ - nltk 3.10.3-1
+ NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-6ww7-3frv-cqxh
CVE-2026-78681 (NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in ...)
- TODO: check
+ - nltk 3.10.3-1
+ NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-97qj-x29f-37w7
CVE-2026-78680 (NLTK versions before 3.10.3 fail to use validated absolute paths when ...)
- TODO: check
+ - nltk 3.10.3-1
+ NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-6hwm-xvph-95vm
CVE-2026-78679 (GitPython before 3.1.59 contains an arbitrary file read vulnerability ...)
TODO: check
CVE-2026-78678 (GitPython versions before 3.1.59 contain an incomplete denylist in the ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c01429387f40e752084a119bf48f9a2ca46d0522
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c01429387f40e752084a119bf48f9a2ca46d0522
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/eb50cbcc/attachment.htm>
More information about the debian-security-tracker-commits
mailing list