REDHAT-BUG-2491486: Path Traversal
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path traversal via URL-encoded path separators and traversal segments when using the nltk: URL scheme. The unsafe-path regex check is performed before url2pathname() decodes the %xx sequences (a classic decode-after-check / TOCTOU-style flaw), allowing an attacker to bypass the protection documented in NLTK's SECURITY.md and read arbitrary files from the filesystem. While literal traversal strings such as ../../../etc/passwd are correctly blocked, encoded variants such as %2fetc%2fpasswd, %2e%2e%2f..., and ..%2f..%2f slip past the regex and are subsequently decoded into a real filesystem path. This vulnerability is fixed in 3.10.0-rc1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NLTK (Natural Language Toolkit)to a version that resolves this vulnerability.Fixed in 3.10.0-rc1
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2491486?
The severity of REDHAT-BUG-2491486 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2491486?
To fix REDHAT-BUG-2491486, update to NLTK version 3.10.0-rc1 or later.
What type of vulnerability is REDHAT-BUG-2491486?
REDHAT-BUG-2491486 is a path traversal vulnerability.
What does the vulnerability in REDHAT-BUG-2491486 affect?
The vulnerability affects the nltk.data.load() function in the Natural Language Toolkit (NLTK).
When was REDHAT-BUG-2491486 published?
REDHAT-BUG-2491486 was published on June 22, 2026.