{"apiVersion":"1.0","identifier":"CVE-2026-78682","description":"NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that is never re-validated. An attacker can supply a validated public URL that the proxy forwards to an internal loopback-only service, allowing disclosure of internal HTTP resources, loading of forged downloader indexes, and installation of attacker-chosen package content.","publishedAt":"2026-08-25T02:16:52","lastModifiedAt":"2026-08-25T16:17:27","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78682","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","epssProbability":0.00245,"riskScore":0.77,"affectedProduct":"NLTK","affectedVersions":"<3.10.3","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-78682","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-78682","en":"https://www.redsauce.net/en/cves/CVE-2026-78682","fr":"https://www.redsauce.net/fr/cves/CVE-2026-78682","pt":"https://www.redsauce.net/pt/cves/CVE-2026-78682","de":"https://www.redsauce.net/de/cves/CVE-2026-78682","sk":"https://www.redsauce.net/sk/cves/CVE-2026-78682","el":"https://www.redsauce.net/el/cves/CVE-2026-78682"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-78682"}}