Multiple NLTK Vulnerabilities Discovered in Ubuntu Releases

Multiple NLTK Vulnerabilities Discovered in Ubuntu Releases

First seen 26 May 2026, 15:30 UTC UbuntuLinuxsecurity 92% similarity 70.5

Article Content

Browse articles
ThreatCluster

Recent vulnerabilities in the Natural Language Toolkit (NLTK) have been identified, affecting several Ubuntu LTS versions including 18.04, 20.04, 22.04, 24.04, and 26.04. These vulnerabilities include improper file path validation (CVE-2026-0846, CVE-2026-0847) that could lead to information disclosure, and a failure to validate external Java archive files (CVE-2026-0848) that could allow arbitrary code execution. The issues were disclosed on May 25, 2026, and affect various components of NLTK, including the WordNet browser application, which is susceptible to cross-site scripting and denial of service attacks (CVE-2026-33230, CVE-2026-33231). Users are advised to update their systems to mitigate these risks. The vulnerabilities were published between March 4 and March 20, 2026, with proof of concepts available for some. The scope of impact is significant given the number of affected Ubuntu versions.

Key Points: • NLTK vulnerabilities affect multiple Ubuntu LTS versions, risking sensitive data exposure. • CVE-2026-0848 allows arbitrary code execution via improperly validated Java archive files. • Users are urged to update to the latest package versions to mitigate these vulnerabilities.

ThreatCluster AI

Timeline

2026-03-04
CVE-2026-0847 published
NLTK's improper file path validation could lead to sensitive information exposure.
Ubuntu
2026-03-05
CVE-2026-0848 published
NLTK fails to validate external Java archive files, risking arbitrary code execution.
Ubuntu
2026-03-09
CVE-2026-0846 published
Improper file path validation in nltk.util could expose sensitive information.
Ubuntu
2026-03-20
CVE-2026-33230 published
Cross-site scripting vulnerability in NLTK's WordNet browser application identified.
Ubuntu
2026-03-20
CVE-2026-33236 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-20
CVE-2026-33231 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-25
Security notice published
Ubuntu issued USN-8302-1 detailing multiple vulnerabilities in NLTK.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story