Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gf32-cmjh-8m9v | Duplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection |
Tue, 15 Sep 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | NLTK before 3.9.3 Missing Post-Download Integrity Verification | nltk: NLTK before 3.9.3 Missing Post-Download Integrity Verification |
| CPEs | ||
| Metrics |
cvssV4_0
|
Mon, 14 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Wed, 02 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 24 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 22 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation. | |
| Title | NLTK before 3.9.3 Missing Post-Download Integrity Verification | |
| First Time appeared |
Nltk
Nltk nltk |
|
| Weaknesses | CWE-494 | |
| CPEs | cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nltk
Nltk nltk |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T23:10:03.270Z
Reserved: 2026-07-16T12:13:18.733Z
Link: CVE-2026-63310
Updated:
Status : Rejected
Published: 2026-08-22T15:16:19.100
Modified: 2026-09-15T00:16:57.827
Link: CVE-2026-63310
OpenCVE Enrichment
Updated: 2026-08-22T16:00:12Z
Github GHSA