[Git][security-tracker-team/security-tracker][master] Add new batch of nltk issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 27 21:15:02 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b38d76a2 by Salvatore Bonaccorso at 2026-08-27T22:14:32+02:00
Add new batch of nltk issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -19,17 +19,23 @@ CVE-2026-81743 (Affected versions of Flowintel allow the LOG_FILE configuration
CVE-2026-81735 (startServer.ts in the mcp-http-server package of UI-TARS-desktop defau ...)
NOT-FOR-US: mcp-http-server
CVE-2026-81727 (NLTK versions before 3.10.3 contain a filesystem containment bypass vu ...)
- TODO: check
+ - nltk 3.10.3-1
+ NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-f794-5jv7-7672
CVE-2026-81726 (NLTK through 3.10.3 contains a path traversal vulnerability in model-a ...)
- TODO: check
+ - nltk <unfixed>
+ NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-8mgp-746c-j5xp
CVE-2026-81725 (NLTK before 3.10.3 contains a regular expression denial of service vul ...)
- TODO: check
+ - nltk 3.10.3-1
+ NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-8mpw-7fpc-4gqj
CVE-2026-81724 (NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in ...)
- TODO: check
+ - nltk 3.10.3-1
+ NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-cw6x-m8jw-qmrh
CVE-2026-81723 (NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnera ...)
- TODO: check
+ - nltk 3.10.3-1
+ NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-vp2x-qp44-57v7
CVE-2026-81722 (nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an ...)
- TODO: check
+ - nltk 3.10.3-1
+ NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-ww6m-cw3f-q94g
CVE-2026-81721 (openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in ...)
TODO: check
CVE-2026-81720 (openssl_encrypt before 1.4.9 fails to validate the memory_cost paramet ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b38d76a28c4d10dbf651077c2d20ff064c774203
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b38d76a28c4d10dbf651077c2d20ff064c774203
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/214655d6/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list