What is CVE-2026-12372?
CVE-2026-12372 is a Server-Side Request Forgery (SSRF) vulnerability in NLTK version 3.9.4 and the develop branch, where the `nltk.pathsec.validate_network_url()` function fails to block IPs in the RFC 6598 shared address space (`100.64.0.0/10`). This flaw could allow attackers to bypass SSRF protections and potentially achieve remote code execution. Users should upgrade to the latest patched version.
Azərbaycanca: CVE-2026-12372, NLTK kitabxanasının 3.9.4 versiyasında və develop branch-da `nltk.pathsec.validate_network_url()` funksiyasındakı Server-Side Request Forgery (SSRF) zəifliyidir. Bu boşluq RFC 6598 üzrə paylaşılan ünvan məkanındakı (`100.64.0.0/10`) IP-ləri bloklamadığı üçün uzaqdan kod icrasına səbəb ola bilər. İstifadəçilərə ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which version of NLTK is affected by CVE-2026-12372?
The vulnerability exists in NLTK version 3.9.4 and the develop branch.
How can the SSRF protection in CVE-2026-12372 be bypassed?
The `nltk.pathsec.validate_network_url()` function does not block IPs in the RFC 6598 shared address space (`100.64.0.0/10`), allowing protection bypass.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.