Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d28c0d86 by Salvatore Bonaccorso at 2026-08-22T21:49:02+02:00
Add new batch of nltk issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -45,11 +45,14 @@ CVE-2026-75870 (Punk versions before 0.18 for Perl allow 
session cookie forgery
 CVE-2026-75866 (Punk::OAuth2::Server versions through 0.03 for Perl issue 
access token ...)
        TODO: check
 CVE-2026-71514 (NLTK 3.9.4 through 3.10.2 contains a path traversal 
vulnerability in C ...)
-       TODO: check
+       - nltk 3.10.3-1
+       NOTE: Fixed by: 
https://github.com/nltk/nltk/commit/10d34b3f4fe3fec74b76527a409eb0acbac2e8ab 
(v3.10.3-rc1)
 CVE-2026-71513 (NLTK before 3.10.3 contains a remote code execution 
vulnerability in A ...)
-       TODO: check
+       - nltk <unfixed>
+       NOTE: Fixed by: 
https://github.com/nltk/nltk/commit/c3e37113742a1ebeeb4f2ca58941f320f98805ea 
(v3.10.3-rc1)
 CVE-2026-70626 (NLTK versions before 3.9.4 contain a symlink escape 
vulnerability in C ...)
-       TODO: check
+       - nltk 3.10.0-1
+       NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-r6gq-whwq-mvg9
 CVE-2026-6258
        REJECTED
 CVE-2026-68769
@@ -73,23 +76,33 @@ CVE-2026-66917 (Joomla Extension - joomgalleryfriends.net - 
Stored XSS in JoomGa
 CVE-2026-66916 (Joomla Extension - joomgalleryfriends.net - Password-Protected 
Categor ...)
        NOT-FOR-US: Joomla
 CVE-2026-66393 (NLTK versions before 3.9.4 contain an unbounded recursion 
vulnerabilit ...)
-       TODO: check
+       - nltk 3.10.0-1
+       NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-rf74-v2fm-23pw
 CVE-2026-65915 (NLTK versions before 3.10.0 contain a logic bug in 
FileSystemPathPoint ...)
-       TODO: check
+       - nltk 3.10.0-1
+       NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-72r2-7mfr-5xr9
 CVE-2026-63312 (NLTK before 3.10.0 contains an arbitrary local file read 
vulnerability ...)
-       TODO: check
+       - nltk 3.10.0-1
+       NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-x5ph-mj9p-rfr8
 CVE-2026-63311 (NLTK before 3.10.0 (affected versions <= 3.9.4) contains a 
server-side ...)
-       TODO: check
+       - nltk 3.10.0-1
+       NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-3gqm-fcw5-w839
 CVE-2026-63310 (NLTK before 3.9.3 fails to verify file integrity after 
downloading pac ...)
-       TODO: check
+       - nltk 3.9.3-1
+       NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-5wp5-5229-5g6q
 CVE-2026-62388 (NLTK versions before 3.10.0 default to ENFORCE=False in 
pathsec.py, ca ...)
-       TODO: check
+       - nltk 3.10.0-1
+       NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-p3m8-78j2-g5p3
 CVE-2026-62385 (NLTK versions before 3.10.0 contain a path traversal 
vulnerability in  ...)
-       TODO: check
+       - nltk 3.10.0-1
+       NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-568f-pv23-39p4
 CVE-2026-62384 (NLTK versions before 3.10.2 contain a symlink-based sandbox 
bypass in  ...)
-       TODO: check
+       - nltk 3.10.3-1
+       NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv
+       NOTE: CVE exists because it is possible to bypass the fix for 
CVE-2026-12074
 CVE-2026-62383 (nltk versions before 3.10.2 contain a symlink-based arbitrary 
file rea ...)
-       TODO: check
+       - nltk 3.10.3-1
+       NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-3hhw-38pf-pxj6
 CVE-2026-62382 (PasswordPusher versions v1.45.11 through v2.9.5 contain an 
improper au ...)
        TODO: check
 CVE-2026-62381 (luci-lib-px5g (LuCI) contains a heap-based buffer overflow in 
the nati ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d28c0d86afee1c82a5a85b68a414d7d4aa88b72b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d28c0d86afee1c82a5a85b68a414d7d4aa88b72b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to