[Git][security-tracker-team/security-tracker][master] Add new nltk issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 25 21:32:41 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ac558d59 by Salvatore Bonaccorso at 2026-08-25T22:32:11+02:00
Add new nltk issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -60,11 +60,14 @@ CVE-2026-79769 (Nokogiri versions before 1.19.4 contain a possible invalid (out-
 CVE-2026-79717 (A server-side request forgery (SSRF) vulnerability was found in galaxy ...)
 	TODO: check
 CVE-2026-79676 (NLTK versions before 3.10.3 contain a path traversal vulnerability in  ...)
-	TODO: check
+	- nltk 3.10.3-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-p4rw-rvv2-7xwr
 CVE-2026-79675 (NLTK before 3.10.3 fails to validate JVM options passed through the pe ...)
-	TODO: check
+	- nltk 3.10.3-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-m4rf-3fr8-xwx3
 CVE-2026-79674 (NLTK versions before 3.10.3 contain a path sandbox bypass vulnerabilit ...)
-	TODO: check
+	- nltk 3.10.3-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-3gq4-3j92-5w49
 CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:rea ...)
 	TODO: check
 CVE-2026-79672 (Ech0 before 4.4.3 fails to enforce scope-based authorization on nine c ...)
@@ -98,7 +101,8 @@ CVE-2026-79659 (Ech0 before 4.7.3 contains a server-side request forgery vulnera
 CVE-2026-79658 (Ech0 before 5.0.1 does not impose any size or shape limit on the Accep ...)
 	TODO: check
 CVE-2026-79657 (NLTK versions before 3.10.3 contain a remote code execution vulnerabil ...)
-	TODO: check
+	- nltk 3.10.3-1
+	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-x99w-6fgc-pmfw
 CVE-2026-79655 (A flaw was found in sos clean, a utility within the sos package. This  ...)
 	TODO: check
 CVE-2026-79652 (A flaw was found in the JWT Bearer authorization grant implementation  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac558d594c8748dd5eb1e40f0257dc3ecdd2acb4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac558d594c8748dd5eb1e40f0257dc3ecdd2acb4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/6365c6d9/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list