Hi, The following vulnerability was published for nltk. CVE-2026-33231[0]: | NLTK (Natural Language Toolkit) is a suite of open source Python | modules, data sets, and tutorials supporting research and | development in Natural Language Processing. In versions 3.9.3 and | prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown | of the local WordNet Browser HTTP server when it is started in its | default mode. A simple `GET /SHUTDOWN%20THE%20SERVER` request causes | the process to terminate immediately via `os._exit(0)`, resulting in | a denial of service. Commit bbaae83db86a0f49e00f5b0db44a7254c268de9b | patches the issue. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-33231 https://www.cve.org/CVERecord?id=CVE-2026-33231 [1] https://github.com/nltk/nltk/security/advisories/GHSA-jm6w-m3j8-898g [2] https://github.com/nltk/nltk/commit/1b6a569d7bab2c697bc1fc245f55ac0102079c18 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
nltk, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1131459@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Mo Zhou <lumin@debian.org> (supplier of updated nltk package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 12 Jul 2026 20:22:26 -0700
Source: nltk
Architecture: source
Version: 3.10.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Science Maintainers <debian-science-maintainers@lists.alioth.debian.org>
Changed-By: Mo Zhou <lumin@debian.org>
Closes: 1116271 1131457 1131459 1131460 1141500
Changes:
nltk (3.10.0-1) unstable; urgency=medium
.
* New upstream version 3.10.0
+ Fix CVE-2026-33230 (Closes: #1131457)
+ Fix CVE-2026-33231 (Closes: #1131459)
+ Fix CVE-2026-33236 (Closes: #1131460)
+ Fix CVE-2026-54293 (Closes: #1141500)
* Upgrade debian/watch to version 5.
* Drop prover9 from Recommends for not being in unstable. (Closes: #1116271)
Checksums-Sha1:
7db87b4629ce3cd81f6fd8b1b5193c9be302e661 1963 nltk_3.10.0-1.dsc
42d96f74de2559274d5225cf449bd33f2b8310f8 3062002 nltk_3.10.0.orig.tar.gz
3c2fcd42dea8c622cf1ec129dcc26cba66c6b39d 8972 nltk_3.10.0-1.debian.tar.xz
8d1216701fb276c778674ec89aef6c7d38170ccc 6210 nltk_3.10.0-1_source.buildinfo
Checksums-Sha256:
917107b1784c3a15e361bbb51bde27e3001f2e7d16c8d3a01adeb9a8eeef91c2 1963 nltk_3.10.0-1.dsc
54e05f99e86399a793315265c3a3e8c7508245baec5399581e4d7eade1a3380d 3062002 nltk_3.10.0.orig.tar.gz
40874b054dce73c2597c389247317fa23a3824d0a9bb82638da10a05bb573ee5 8972 nltk_3.10.0-1.debian.tar.xz
c4b852946d39b0925dce69cbc9527918c145c614edcd758f3a05d86c759c1891 6210 nltk_3.10.0-1_source.buildinfo
Files:
2ddd6dc48a3bce5432efbed1085c5eb9 1963 science optional nltk_3.10.0-1.dsc
30520272e261433f8d9440a2fa917d6e 3062002 science optional nltk_3.10.0.orig.tar.gz
1f47b3eae35442da8a405fa8661213c5 8972 science optional nltk_3.10.0-1.debian.tar.xz
d1d67ce5bbd568399e16acdb36f5af2c 6210 science optional nltk_3.10.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJFBAEBCgAvFiEEY4vHXsHlxYkGfjXeYmRes19oaooFAmpUWi8RHGx1bWluQGRl
Ymlhbi5vcmcACgkQYmRes19oaor6PBAAkvS+JunQgmojSZ3+TO4LWZc5jLa4a0oa
Aj0flDe/w5CXTk5++tkgrPA4VmWRWAGJy2SxKjtRlOTFn8ALZMWq0vBChzvw0g3y
AVwEcAd7sFiLS4KqjpgvhnMtgLlbaKdIA0dmycG21tYDLIm8BXc7vCA6gpZbqll4
TfYVaJ23dsmxIurCn31AcOJCcwuhZpss8/m/tSwnuWPjfvANhm0eSNOIYy0aPyuR
TgMpTLo5wzHGB0ctcM76GsVP/T1wEdEW36qddVHktjm4reTPfU8koeWVBTXZzmqB
SQ1D+su1IZTyIpuuQRSAAChCs/SXl7vhVAqMN8F810jdNmeStS3aNkkQcCwbvIGP
95fTQzAAislBAngExqLzMgAfxsxc9LKskCKiy4yvV5zuWLbEccELhC8eYQTwLWeo
3qSrOAx+q85eNlfFnfXIqkoYbtHqTPZ0ia+YnH4IpRoMw6+eoS0H9YzcUQ3Fdq+Z
iEULIPA9C9PjoMKvciZV2bnhx6xxPifnZMUGU9xW+Gt47F9xFfHG1jbM2VusHqma
l6C9x31v1GpmTbAORFESPFlrwdqWoiUuxaw+gCl/lQ70lVf+nftRG/tfo399Nd5l
M1ojMITZK4Ge5r04SZ/hFHJz3cwYO4ZuEYVrkII+jtpOLS6pFd86KGV1e9LSY46K
gCQiUiewlQs=
=8XSS
-----END PGP SIGNATURE-----