[Git][security-tracker-team/security-tracker][master] Add CVE-2025-14009/nltk

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Feb 19 09:03:17 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0a2974c1 by Salvatore Bonaccorso at 2026-02-19T10:02:58+01:00
Add CVE-2025-14009/nltk

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -517,7 +517,10 @@ CVE-2025-14444 (The RegistrationMagic \u2013 Custom Registration Forms, User Reg
 CVE-2025-14340 (Cross-site scripting in REST Management Interface in Payara Server <4. ...)
 	NOT-FOR-US: Payara
 CVE-2025-14009 (A critical vulnerability exists in the NLTK downloader component of nl ...)
-	TODO: check
+	- nltk <unfixed>
+	NOTE: https://huntr.com/bounties/49ecbc02-054e-4470-b2e0-b267936cc4e4
+	NOTE: https://github.com/nltk/nltk/issues/3489
+	NOTE: https://github.com/nltk/nltk/pull/3468
 CVE-2025-13965
 	REJECTED
 CVE-2025-13933



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0a2974c11f07e85c04518efda5802291fa021a3d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0a2974c11f07e85c04518efda5802291fa021a3d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260219/6e7393d8/attachment.htm>


More information about the debian-security-tracker-commits mailing list