⚠ Withdrawn by GitHub Security Advisories
Withdrawn: September 9, 2026
GHSA-gf32-cmjh-8m9vCriticalCVSS 7.1
Duplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
🔗 CVE IDs covered (1)
📋 Description
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-5wp5-5229-5g6q. This link is maintained to preserve external references.
Original Description
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
🎯 Affected products1
- pip/nltk:<= 3.9.2