CVE-2026-12372Disclosure(nltk / nltk)

LOWCVSS 3.7 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared address space (`100.64.0.0/10`). This occurs because Python's `ipaddress` module does not classify such addresses as `is_private` or `is_global`, and the current guard only checks `is_private` and a few explicit categories. An attacker who can influence a URL passed to NLTK's network-loading helpers can exploit this vulnerability to make a strict-mode application send requests to shared-address-space hosts, potentially exposing non-public infrastructure reachable from the application host. The impact is limited to SSRF-style confidentiality exposure, with no code execution claimed.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nltk

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
nltk

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-10: 3Technical Details · 2026-08-10: 208-10
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-12372 A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` functi… https://www.cve.org/CVERecord?id=CVE-2026-12372

    Post summary

    The text reports the discovery of a new Server‑Side Request Forgery vulnerability in nltk/nltk affecting versions 3.9.4 and the develop branch, with no evidence of active exploitation or available fixes.

    000101.3K
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12372 A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` functi… https://www.cve.org/CVERecord?id=CVE-2026-12372 ----- Traducción: CVE-2026-12372 Exi… http://infoflow.cloud`

    Post summary

    CVE‑2026‑12372 is disclosed as a SSRF flaw in nltk 3.9.4 and the develop branch, with version info and a reference to the CVE record; no PoC, exploit, or patch is mentioned.

    0000032
    98 followersView on X
  • VulDB 🛡@vuldb
    General

    Attention, elevated activities detected targeting NLTK (CVE-2026-12372) https://vuldb.com/vuln/387288/cti

    Post summary

    Alert announces elevated activity targeting NLTK (CVE-2026-12372) and includes a link to a vulnerability database, but no further technical or exploit details are provided.

    00000124
    2.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnltknltk3.9.4--

Explore more