Skip to content
EXPLOIT
.CC
CVEs
Search
About
synced 17 MIN AGO
T-17M
01
Record
STATE: —
02
Description
SRC: CNA
03
Metadata
SCHEMA: CVE JSON 5
04
Affected products
PAIRS: —
05
References
REFS: —
01
Record
STATE: PUBLISHED
CVE-2026-71513
NLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name Bypass
High
PUBLISHED
CNA: VulnCheck
Base score
8.7
CVSS v4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
View raw JSON
CVE Program record
02
Description
CNA: VulnCheck
NLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name Bypass
03
Metadata
SCHEMA: 5.2
Published
2026-08-22 13:34Z
6 HR AGO
Last updated
2026-08-22 13:34Z
6 HR AGO
Reserved
2026-08-06
Assigning CNA
VulnCheck
Record state
PUBLISHED
Severity
High (CVSS 8.7)
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Weaknesses
CWE-502
Deserialization of Untrusted Data
Base
SSVC decision
No CISA-ADP assessment
Data version
5.2
Document digest
b20e2a2d98aab8bfe2babb169fd1e90d54b3096b5b28df1fb639e9894328d0f3
04
Affected products
PAIRS: 1
Vendor
Product
Versions
Platforms
nltk
nltk
3.10.0 to < 3.10.3
—
05
References
REFS: 4
github.com
Patch Commit
https://github.com/nltk/nltk/commit/c3e37113742a1ebeeb4f2ca58941f320f98805ea
patch
github.com
https://github.com/nltk/nltk
product
github.com
https://github.com/nltk/nltk/blob/v3.10.2/nltk/picklesec.py#L119-L124
technical-description
www.vulncheck.com
VulnCheck Advisory: NLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name Bypass
https://www.vulncheck.com/advisories/nltk-through-remote-code-execution-via-allowlistunpickler-dotted-name-bypass
third-party-advisory