THREAT OPS › Threat News › [NVD] CVE-2026-12372 (LOW 3.7) — A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared a
[NVD] CVE-2026-12372 (LOW 3.7) — A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared a
CVE-2026-12372 CVSS: 3.7 LOW Published: 2026-08-09T23:16:35.793
A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared address space (`100.64.0.0/10`). This occurs because Pyt
Indicators of compromise
- CVE-2026-12372cve
- 100.64.0.0ipv4
- 100.64.0.0/10cidr
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12372