Skip to content
NLTK Mass Disclosure — 4 CVEs, Peak 9.8 (Allowlisted Pickle RCE) ThreatAft — Cybersecurity Intelligence / 12h A mass disclosure of four CVEs across versions before 3.10.3 just dropped, with CVE-2026-79657 leading at CVSS 9.8 — an unsafe pickle deserialization vulnerability where allowlisted pickle loaders trust entire module namespaces, allowing arbitrary code execution via crafted model files. CVSS 9.8 — Critical pickle deserialization RCE — CVE-2026-79657 allows attackers to execute arbitrary

NLTK Mass Disclosure — 4 CVEs, Peak 9.8 (Allowlisted Pickle RCE) ThreatAft — Cybersecurity Intelligence / 12h A mass disclosure of four CVEs across versions before 3.10.3 just dropped, with CVE-2026-79657 leading at CVSS 9.8 — an unsafe pickle deserialization vulnerability where allowlisted pickle loaders trust entire module namespaces, allowing arbitrary code execution via crafted model files. CVSS 9.8 — Critical pickle deserialization RCE — CVE-2026-79657 allows attackers to execute arbitrary

threataft.com • August 26, 2026

NLTK is the natural language processing toolkit used by thousands of NLP/ML pipelines, security tools, and research environments. A mass disclosure of four CVEs across versions before 3.10.3 just dropped, with CVE-2026-79657 leading at CVSS 9.8 — an unsafe pickle deserialization vulnerability where allowlisted pickle loaders trust entire module namespaces, allowing arbitrary code execution via crafted model files. If you run Python automation that uses NLTK, this is a critical supply chain story.

📌 TL;DR — NLTK Mass Disclosure: 4 CVEs, Peak 9.8

What happened: NLTK disclosed four CVEs across versions before 3.10.3. CVE-2026-79657 (CVSS 9.8) is an unsafe pickle deserialization vulnerability where allowlisted pickle loaders trust entire module namespaces enabling RCE. Additional CVEs include XML entity expansion DoS, SSRF via proxy handler, and unsafe pickle deserialization in TransitionParser.parse(). Critical patches: CVE-2026-79657 (9.8) — allowlisted pickle loaders trust entire module namespaces → RCE. CVE-2026-78683 (9.6) — unsafe pickle deserialization → RCE. CVE-2026-78681 (8.7) — XML entity expansion DoS. CVE-2026-78682 (7.5) — SSRF via proxy handler. Impact: RCE, file disclosure, denial of service, credential theft. Affected versions: NLTK before 3.10.3. Active exploitation: No known exploitation at time of publication. Defender actions: Update to NLTK 3.10.3 immediately. Audit model file sources. Review proxy configurations.

Weakness Types: CWE-502 (Deserialization of Untrusted Data), CWE-776 (XML Entity Expansion), CWE-918 (Server-Side Request Forgery).

Fixed Version: All CVEs are fixed in NLTK 3.10.3.

⚠️ Critical Patches Available: Update NLTK to 3.10.3+ immediately. Audit model file sources.

CVE-2026-79657 is the highest-severity vulnerability in this disclosure, carrying a CVSS 3.1 base score of 9.8 (Critical) .

The vulnerability exists in NLTK's allowlisted pickle loaders, which trust entire module namespaces when deserializing pickle data. An attacker can craft a malicious pickle payload that, when loaded, resolves arbitrary classes from trusted modules, enabling arbitrary code execution with the privileges of the user running NLTK.

This is a classic deserialization vulnerability (CWE-502) where the allowlist is too permissive — trusting entire module namespaces rather than specific safe classes.

Affected versions: NLTK before 3.10.3.

Fixed version: 3.10.3.

CVE-2026-78683 is a critical deserialization vulnerability in TransitionParser.parse() ( nltk/parse/transitionparser.py ), carrying a CVSS 3.1 base score of 9.6 (Critical) .

The method calls pickle_load() with the default restricted=False , routing deserialization through WarningUnpickler , which does not override find_class() and therefore permits arbitrary class resolution.

When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code.

Critical detail: NLTK provides a RestrictedUnpickler for safe deserialization, but it is not used by production code paths.

Affected versions: NLTK before 3.10.0 (fixed), but 3.10.3 is the recommended upgrade.

Fixed version: 3.10.0.

CVE-2026-78681 is a high-severity denial of service vulnerability in NLTK's XML parsing, carrying a CVSS 4.0 base score of 8.7 (High) and a CVSS 3.1 base score of 7.5 .

NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules. The parser honors entity declarations in document DTDs, allowing attackers to craft XML payloads with deeply nested entity declarations that expand from hundreds of bytes to megabytes in memory.

This is a classic XML Entity Expansion (Billion Laughs) attack, classified under CWE-776: Improper Restriction of Recursive Entity References in DTDs .

Affected versions: NLTK before 3.10.3.

Fixed version: 3.10.3.

CVE-2026-78682 is a server-side request forgery vulnerability in NLTK's pathsec.urlopen function, carrying a CVSS 3.1 base score of 7.5 (High) .

The vulnerability affects nltk.pathsec.urlopen and callers nltk.data.load , nltk.downloader.Downloader.index/download when an HTTP proxy is configured.

pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers, so the actual fetch is performed by the proxy against a destination that is never re-validated.

Attackers can supply a validated public URL that the proxy forwards to an internal loopback-only service, allowing disclosure of internal HTTP resources.

Affected versions: NLTK before 3.10.3.

Fixed version: 3.10.3.

Update NLTK to version 3.10.3 or later.

Audit model file sources. For CVE-2026-79657 and CVE-2026-78683 , ensure all pickle model files loaded by NLTK are from trusted sources.

Review proxy configurations. For CVE-2026-78682 , audit HTTP proxy settings in environments using NLTK downloaders.

NLTK is used in thousands of NLP/ML pipelines, security tools, and research environments. A mass disclosure of four CVEs across versions before 3.10.3 has dropped — CVE-2026-79657 leading at CVSS 9.8. Allowlisted pickle loaders trust entire module namespaces, allowing attackers to execute arbitrary code via crafted model files.

NLTK provides a RestrictedUnpickler for safe deserialization, but it is not used by production code paths. This is a supply chain problem. If an attacker can control a model file loaded by your NLP pipeline, they can execute code in your environment.

Update NLTK to 3.10.3 immediately. Audit model file sources. Review proxy configurations.

— The ThreatAft Security Team

ThreatAft is an independent security publication. This analysis is based on research published by NVD, GitHub, and other security sources as of August 2026. Vulnerability information is time-sensitive; always refer to official sources for the most current guidance.