Server-Side Request Forgery Vulnerability in NLTK by NLTK Project
CVE-2026-78682

8.7HIGH

Key Information:

Vendor

Nltk

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-78682?

NLTK, prior to version 3.10.3, is vulnerable to a server-side request forgery (SSRF) issue arising when an HTTP proxy is set up. The vulnerability allows an attacker to exploit the system via the pathsec.urlopen method and its associated functions. In this scenario, the local hostname validation is bypassed due to the proxy-handler inheritance, leading to potential exposure of internal HTTP resources. This enables the execution of forged downloader indexes and installation of malicious packages. Users of NLTK are urged to review the advisory for mitigation steps.

Affected Version(s)

nltk 0 < 3.10.3

nltk 3.10.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sondt99
.