CVE-2026-63311 | NLTK up to 3.9.4 nltk/pathsec.py validate_network_url server-side request forgery (Nessus ID 339016)
A vulnerability identified as critical has been detected in NLTK up to 3.9.4. This affects the function validate_network_url of the file nltk/pathsec.py. Performing a manipulation results in server-side request forgery.
This vulnerability is reported as CVE-2026-63311. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.