Junglewise Threat Intelligence

CVE-2026-0846: NLTK arbitrary file read in nltk.util.filestring

CVE-2026-0846 · Severity: high · CVSS 8.6 · Published 2026-03-09

Technologies: Red Hat OpenShift Lightspeed, Red Hat Lightspeed Core, Red Hat Ansible Automation Platform 2, NLTK Project Natural Language Toolkit, nltk (PyPI). Vendors: Red Hat, NLTK Project, PyPI.

Executive brief

A vulnerability in the NLTK library, a popular tool for processing human language data, allows unauthorized access to files on a server. If an application using this library accepts user input without proper checks, an attacker could read sensitive system files or configuration data. This could lead to the exposure of private information or credentials, potentially compromising the entire system.

Technical details

A path traversal vulnerability exists in the `filestring()` function of the `nltk.util` module in NLTK version 3.9.2. The root cause is improper validation of input paths, where the function directly opens files specified by user input without sanitization. An attacker can exploit this by providing absolute paths or traversal sequences (e.g., ../) to access sensitive system files. The vulnerability is reachable if the application exposes this function through a web API or any interface accepting user-supplied strings. Red Hat has issued security advisories (RHSA-2026:10184, RHSA-2026:19712) addressing this in their OpenShift AI and related products.

Affected products

  • nltk nltk 3.9.2
  • Red Hat Red Hat OpenShift AI 2.25, 3.3
  • Red Hat Red Hat Ansible Automation Platform 2 2
  • Red Hat Red Hat Lightspeed Core
  • Red Hat OpenShift Lightspeed

Timeline

  • 2026-03-09: disclosed: Initial disclosure via huntr.dev
  • 2026-03-09: advisory: NVD published date
  • 2026-04-23: patched: Red Hat released security advisory RHSA-2026:10184
  • 2026-05-20: patched: Red Hat released security advisory RHSA-2026:19712

References

Related threats