Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-63310

Опубликовано: 22 авг. 2026
Источник: debian

Описание

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nltkfixed3.9.3-1package
nltkno-dsatrixiepackage

Примечания

  • https://github.com/nltk/nltk/security/advisories/GHSA-5wp5-5229-5g6q

Связанные уязвимости

CVSS3: 7.1
ubuntu
13 дней назад

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

CVSS3: 7.1
redhat
13 дней назад

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

CVSS3: 7.1
nvd
13 дней назад

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

CVSS3: 7.1
github
13 дней назад

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.