THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-12372 (LOW 3.7) — A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared a

[NVD] CVE-2026-12372 (LOW 3.7) — A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared a

mednvdPublished 2026-08-09

CVE-2026-12372 CVSS: 3.7 LOW Published: 2026-08-09T23:16:35.793

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared address space (`100.64.0.0/10`). This occurs because Pyt

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12372