THREAT OPS › Threat News › [NVD] CVE-2026-63310 (HIGH 7.1) — NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
[NVD] CVE-2026-63310 (HIGH 7.1) — NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
CVE-2026-63310 CVSS: 7.1 HIGH Published: 2026-08-22T15:16:19.100
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
MITRE ATT&CK techniques
- Malicious PackageAML.T0011.001
Indicators of compromise
- CVE-2026-63310cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63310