Loading
Natural Language Toolkit
Does not declare an LLM SDK itself, but depends on a package that does, 3 steps away.
Advisories that name nltk as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| CVE-2026-79675GHSA-m4rf-3fr8-xwx3: NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841) | Critical | <= 3.10.2 | 3.10.3 | 2026-09-01 |
| CVE-2026-54293GHSA-p4gq-832x-fm9v: Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read | High | <= 3.9.4 | 2026-06-16 |
Shortest path through the runtime dependencies of each latest release.
As declared in PyPI metadata for version 3.10.3. Optional extras are listed with their extra name.
Among the packages in the registry; not every dependent on PyPI.