Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gf32-cmjh-8m9v

Опубликовано: 22 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 7.1

Описание

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

EPSS

Процентиль: 2%
0.00116
Низкий

9.3 Critical

CVSS4

7.1 High

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 7.1
ubuntu
10 дней назад

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

CVSS3: 7.1
nvd
13 дней назад

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

CVSS3: 7.1
debian
13 дней назад

NLTK before 3.9.3 fails to verify file integrity after downloading pac ...

EPSS

Процентиль: 2%
0.00116
Низкий

9.3 Critical

CVSS4

7.1 High

CVSS3

Дефекты

CWE-494