CVE-2026-63310
HIGH
NVD
CVSS Score
7.1
Severity
HIGH
Published
Aug 22, 2026
Vendor
unknown
Description
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.