CVE-2026-63310
EUVD-2026-6433522.08.2026, 15:16
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| nltk | nltk | 𝑥 < 3.9.3 | CNA |
Debian Releases
Common Weakness Enumeration