⚠ Withdrawn by GitHub Security Advisories

Withdrawn: September 9, 2026

GHSA-gf32-cmjh-8m9vCriticalCVSS 7.1

Duplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

Published
August 22, 2026
Last Modified
September 9, 2026

🔗 CVE IDs covered (1)

📋 Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-5wp5-5229-5g6q. This link is maintained to preserve external references.

Original Description

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

🎯 Affected products1

  • pip/nltk:<= 3.9.2

🔗 References (4)