Bug 2494748 (CVE-2026-12243) - CVE-2026-12243 nltk: NLTK: Information disclosure via path traversal vulnerability
Summary: CVE-2026-12243 nltk: NLTK: Information disclosure via path traversal vulnerab...
Keywords:
Status: NEW
Alias: CVE-2026-12243
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2494932 2494933
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-30 02:02 UTC by OSIDB Bzimport
Modified: 2026-08-15 08:27 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-30 02:02:00 UTC
NLTK version 3.9.4 is vulnerable to a path traversal attack due to an incomplete fix for GitHub Issue #3504. The `_UNSAFE_NO_PROTOCOL_RE` regex in `nltk/data.py` checks for literal `../` sequences but fails to account for percent-encoded traversal sequences such as `..%2f`. The `url2pathname()` function decodes these sequences after the validation step, allowing an attacker to bypass the protection. This vulnerability enables an attacker to read arbitrary files accessible to the Python process by controlling the resource name parameter passed to `nltk.data.load()` or `nltk.data.find()`. The issue affects applications that rely on NLTK for resource loading, including NLP web applications, Jupyter notebooks, and CLI tools. The default `pathsec.ENFORCE=False` setting exacerbates the impact by not blocking the file read at the `open()` stage.


Note You need to log in before you can comment on or make changes to this bug.