Skip to content
Critical NLTK Vulnerability in Multiple Ubuntu Releases

Critical NLTK Vulnerability in Multiple Ubuntu Releases

First seen 28 Apr 2026, 15:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 29, 2026 at 15:05 UTC
  • •CVE-2025-14009 affects multiple Ubuntu LTS releases from 14.04 to 24.04.
  • •Exploitation could allow attackers to execute arbitrary code via malicious zip files.
  • •Users should update to the latest NLTK package versions to mitigate the vulnerability.

A critical security vulnerability has been identified in the Natural Language Toolkit (NLTK) affecting multiple Ubuntu LTS releases, including 24.04, 22.04, 20.04, 18.04, 16.04, and 14.04. The flaw allows an attacker to exploit the improper handling of file extraction when opening a specially crafted zip file, potentially leading to system crashes or arbitrary code execution. This vulnerability, cataloged as CVE-2025-14009, was published on February 18, 2026. Users are advised to update their systems to the latest package versions to mitigate the risk. The issue is particularly concerning as it affects a wide range of supported Ubuntu versions, increasing the potential attack surface. Ubuntu Pro users are eligible for extended security maintenance. Standard system updates are recommended to apply the necessary patches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 162d ago How this analysis works

Timeline

2026-02-18
CVE-2025-14009 published
2026-04-28
Security advisory released for NLTK vulnerability

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2025-14009 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed