Server-Side Request Forgery Vulnerability in NLTK by NLTK Project
CVE-2026-78682
8.7HIGH
What is CVE-2026-78682?
NLTK, prior to version 3.10.3, is vulnerable to a server-side request forgery (SSRF) issue arising when an HTTP proxy is set up. The vulnerability allows an attacker to exploit the system via the pathsec.urlopen method and its associated functions. In this scenario, the local hostname validation is bypassed due to the proxy-handler inheritance, leading to potential exposure of internal HTTP resources. This enables the execution of forged downloader indexes and installation of malicious packages. Users of NLTK are urged to review the advisory for mitigation steps.
Affected Version(s)
nltk 0 < 3.10.3
nltk 3.10.3
