CVE-2026-63310

Description

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

Statement

Red Hat has rated this issue as having an Impact of Important. This flaw is only exploitable when application code calls NLTK's downloader module (e.g. nltk.download()) to fetch corpora or model packages from the network at runtime, and an attacker is able to intercept or redirect that traffic via a man-in-the-middle position or DNS poisoning. Red Hat products that vendor nltk but do not invoke the downloader at runtime -- for example, images that ship pre-bundled NLTK data baked in at build time -- are not affected by this flaw regardless of the packaged nltk version.

Mitigation

Upgrade the nltk package to version 3.9.3 or later, which adds post-download integrity verification before extraction. Pin this minimum version in requirements files, lockfiles, and container image builds for all affected components.

Where an immediate upgrade is not possible: avoid invoking NLTK's automatic downloader over untrusted or unauthenticated networks. Pre-download and independently verify the required NLTK data packages from a trusted source, host them in an internal, integrity-checked artifact repository, and point NLTK_DATA at that vetted local store so the runtime process never fetches data over the wire. Enforcing TLS with certificate validation and using trusted, DNSSEC-validated resolvers for the download endpoint reduces exposure to MITM/DNS-poisoning attacks but does not substitute for upgrading, since the underlying missing-integrity-check flaw remains present.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.16.57.1
Attack VectorNetworkNetworkNetwork
Attack ComplexityHighHighHigh
Privileges RequiredNoneNoneNone
User InteractionRequiredNoneRequired
ScopeUnchangedUnchangedUnchanged
ConfidentialityLowLowLow
Integrity ImpactHighHighHigh
Availability ImpactHighNoneHigh

Vector

Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H

NVD: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N

cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H

Understanding the Weakness (CWE)

Integrity,Availability,Confidentiality,Other

Technical Impact: Execute Unauthorized Code or Commands; Alter Execution Logic; Other

Executing untrusted code could compromise the control flow of the program. The untrusted code could execute attacker-controlled commands, read or modify sensitive resources, or prevent the software from functioning correctly for legitimate users.

Frequently Asked Questions

Want to get errata notifications? Sign up here.