CVE-2026-78682: NLTK: pathsec SSRF protection can be bypassed when a proxy is configured
Current NLTK source reopens SSRF in proxied environments. pathsec.urlopen() validates the requested hostname locally, but once proxy inheritance is enabled the real fetch is performed by the proxy rather than by the validated direct-connect socket path.
References
- github.com/advisories/GHSA-6ww7-3frv-cqxh
- github.com/nltk/nltk/commit/767333a005a1cd3d82d2029215f2dbe66a5844d9
- github.com/nltk/nltk/releases/tag/v3.10.3
- github.com/nltk/nltk/security/advisories/GHSA-6ww7-3frv-cqxh
- github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3733.yaml
- nvd.nist.gov/vuln/detail/CVE-2026-78682
- www.vulncheck.com/advisories/nltk-before-ssrf-protection-bypass-via-proxy
Code Behaviors & Features
Detect and mitigate CVE-2026-78682 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →