CVE-2026-79657Disclosure(nltk / nltk)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nltk nltk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nltk

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-25); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
nltk

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-25: 2Mentions · 2026-08-30: 1Mentions · 2026-09-02: 1Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-30: 1Patch / Workaround · 2026-09-02: 1Technical Details · 2026-08-25: 2Technical Details · 2026-08-30: 1Technical Details · 2026-09-02: 108-2508-3009-02
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-252
Disclosure2
2026-08-301
Patch1
2026-09-021
Patch1
Full discourse4 posts
  • ざと@hoppiece_
    Patch

    HojiChar v0.17.3 is out! Following the critical NLTK remote code executuion disclosure (CVE-2026-79657), we moved fast and replaced our only NLTK usage with equivalent local code with preserving behavior and performance. https://github.com/HojiChar/HojiChar/releases/tag/v0.17.3

    Post summary

    HojiChar released v0.17.3, patching the critical NLTK CVE‑2026‑79657 by removing the vulnerable library and replacing it with equivalent local code.

    00082726
    1.9K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-79657 (CVSS 9.8) NLTK <3.10.3 allows remote code execution via malicious pickle payloads. Attackers exploit unsafe deserialization to execute arbitrary commands during model loading. Update immediately. #CVE #Vulnerability #PatchNow https://t.co/w49BytlWBC

    Post summary

    The tweet announces the critical CVE‑2026‑79657 affecting NLTK, detailing RCE via unsafe pickle deserialization and urging users to update immediately.

    0000069
    122 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐🚨 NLTK Mass Disclosure — 4 CVEs, CVSS 9.8 PEAK CVE-2026-79657 (9.8): Allowlisted pickle RCE → https://threataft.com/articles/nltk-mass-disclosure-4-cves #cybersecurity #infosec #NLTK #Python #NLP #ML #SupplyChain #RCE #ThreatIntel

    Post summary

    The post announces the disclosure of CVE-2026-79657 with a CVSS score of 9.8, describing it as an allowlisted pickle RCE. No exploit, patch, or active exploitation details are given, but a link to a fuller article is provided.

    0000045
    37 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - NLTK RCE via allowlisted pickle namespace bypass (CVE-2026-79657) NLTK’s allowlisted pickle loaders trust entire module namespaces instead of specific safe callables. A crafted pickle can abuse REDUCE to invoke dangerous callables (e.g., ReppTokenizer._execute or numpy.f2py.crackfortran.myeval) when loading model/tokenizer artifacts, leading to arbitrary command execution. 👉Affected: nltk < 3.10.3 | Upgrade to 3.10.3

    Post summary

    The message announces CVE-2026-79657 as a critical NLTK remote‑code‑execution flaw using malicious pickles, explains how it works, and recommends upgrading to 3.10.3, but no proof of concept, exploit tool, or active exploitation is cited.

    0000057
    294 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnltknltk---

Explore more