CVE-2026-12259 | nltk up to 3.9.4 Downloader nltk.downloader.Downloader._download_package weak password hash

SecurityVulns

A vulnerability was found in nltk up to 3.9.4. It has been declared as problematic. Affected is the function nltk.downloader.Downloader._download_package of the component Downloader. Such manipulation leads to password hash with insufficient computational effort.

This vulnerability is listed as CVE-2026-12259. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More