Server-Side Request Forgery Vulnerability in NLTK Library by NLTK Organization
CVE-2026-12372
3.7LOW
What is CVE-2026-12372?
A vulnerability exists in the NLTK library where the function nltk.pathsec.validate_network_url() does not adequately reject IP addresses from the RFC 6598 shared address space. This oversight permits an attacker to influence the URLs used by NLTK's network-loading features, potentially allowing requests to be sent to non-public infrastructures. As a result, sensitive data may be exposed due to SSRF, although the vulnerability does not enable code execution.
Affected Version(s)
nltk/nltk <= unspecified
