Alerts This Week
Warning Icon 1 561
Alerts This Week
Warning Icon 1 561

Ubuntu 26.04 NLTK Faces Significant Issues in 2026-0846 Release

ubuntu
Calendar Grey May 25, 2026
Dist Ubuntu Esm H88
Critical security updates for NLTK in multiple Ubuntu versions addressing several vulnerabilities and exploits.
Several security issues were fixed in NLTK.

Summary

Several security issues were fixed in NLTK.

Software Description:

- nltk: Natural Language Toolkit

Details:

It was discovered that NLTK incorrectly validated file paths when

opening files using the nltk.util module. An attacker could possibly

use this issue to obtain sensitive information. (CVE-2026-0846)

It was discovered that NLTK incorrectly validated file paths in

multiple CorpusReader classes. An attacker could possibly use

this issue to obtain sensitive information. (CVE-2026-0847)

It was discovered that NLTK did not properly validate external

Java archive files loaded by StanfordSegmenter. An attacker

could possibly use this issue to execute arbitrary code. This

issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu

22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.

(CVE-2026-0848)

It was discovered that NLTK's WordNet browser application

incorrectly handled user-supplied input. An attacker could

possibly use this issue to perform a cross-site scripting

attack....

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
  python3-nltk                    3.9.2-1ubuntu0.1~esm2
                                  Available with Ubuntu Pro

Ubuntu 24.04 LTS
  python3-nltk                    3.8.1-1ubuntu0.1~esm2
                                  Available with Ubuntu Pro

Ubuntu 22.04 LTS
  python3-nltk                    3.7-1ubuntu0.1~esm2
                                  Available with Ubuntu Pro

Ubuntu 20.04 LTS
  python3-nltk                    3.4.5-2ubuntu0.1~esm4
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  python-nltk                     3.2.5-1ubuntu0.1+esm4
                                  Available with Ubuntu Pro
  python3-nltk                    3.2.5-1ubuntu0.1+esm4
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  python-nltk                     3.1-1ubuntu0.1+esm4
                                  Available with Ubuntu Pro
  python3-nltk                    3.1-1ubuntu0.1+esm4
                                  Available with Ubuntu Pro

Ubuntu 14.04 LTS
  python-nltk                     2.0~b9-0ubuntu4.1~esm6
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary
changes.

References

https://ubuntu.com/security/notices/USN-8302-1

CVE-2026-0846, CVE-2026-0847, CVE-2026-0848, CVE-2026-33230,

CVE-2026-33231, CVE-2026-33236

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8302-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here