What is CVE-2026-12259?
CVE-2026-12259 is a vulnerability in NLTK 3.9.4 where the `_download_package()` function writes downloaded packages to disk before enforcing SHA-256 or MD5 checksum validation. This flaw allows an attacker to tamper with the package response via `info.url`, potentially leading to remote code execution. Users should upgrade NLTK immediately and ensure packages are downloaded from trusted sources.
Azərbaycanca: CVE-2026-12259, NLTK 3.9.4 kitabxanasında `_download_package()` funksiyasında aşkar edilmiş kritik zəiflikdir. Bu boşluq, endirilmiş paketlərin SHA-256 və ya MD5 çek-sum yoxlamasından əvvəl diskə yazılmasına imkan verir ki, bu da təcavüzkara `info.url` vasitəsilə paketi manipulyasiya edərək təhlükəli kod yerləşdirməsinə səbəb ola bilər. İstifadəçilər dərhal NLTK kitabxanasını ən son versiyaya yeniləməli və paket bütövlüyünü təmin etmək üçün təhlükəsiz şəbəkə mühitindən əmin olmalıdırlar.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
In which library and function was CVE-2026-12259 discovered?
CVE-2026-12259 was discovered in the `_download_package()` function of the NLTK 3.9.4 library.
How can CVE-2026-12259 be mitigated?
To mitigate CVE-2026-12259, users should immediately upgrade the NLTK library to the latest version and ensure packages are downloaded only from trusted sources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.