Server-Side Request Forgery Vulnerability in NLTK Library by NLTK Organization
CVE-2026-12372

3.7LOW

Key Information:

Vendor

Nltk

Status
Vendor
CVE Published:
9 August 2026

What is CVE-2026-12372?

A vulnerability exists in the NLTK library where the function nltk.pathsec.validate_network_url() does not adequately reject IP addresses from the RFC 6598 shared address space. This oversight permits an attacker to influence the URLs used by NLTK's network-loading features, potentially allowing requests to be sent to non-public infrastructures. As a result, sensitive data may be exposed due to SSRF, although the vulnerability does not enable code execution.

Affected Version(s)

nltk/nltk <= unspecified

References

CVSS V3.0

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.