- Sources: nltk/nltk repository advisory GHSA-5wp5-5229-5g6q, GitHub advisory GHSA-gf32-cmjh-8m9v
- Summary: NLTK's downloader fetches a package archive and extracts it without checking the bytes that arrived against an expected checksum. The checksum logic already exists in the downloader and is only ever called before a download, as an is-this-already-installed status check. The repository advisory, published on 2026-08-07 by the reporter credited as ekaf, gives affected versions as 3.9.2 and earlier with the fix in 3.9.3 or later, and rates it High with no CVE assigned at publication. The two sources disagree on severity, because the GitHub Advisory Database entry is an unreviewed NVD import that arrived on 2026-08-22 at 15:31 UTC as CVE-2026-63310 and rates it CVSS v4 9.3.
- Why it matters: The integrity check the downloader appears to perform never applies to the bytes it extracts, so an NLTK corpus install on 3.9.2 or earlier unpacks whatever arrived, and 3.9.3 is the stated fix.
send feedback on this story