OSV 1.4.0 · github-reviewed · 修改于 2026-09-02 22:40
发布时间
2026-08-25 11:32
GitHub 审查时间
2026-09-02 22:40
NVD 发布时间
2026-08-25 10:16
源文件
advisories/github-reviewed/2026/08/GHSA-crp9-r7rq-c8cg/GHSA-crp9-r7rq-c8cg.json
该公告已于 2026-09-02 22:40 撤回
内容仅用于保留外部引用,请不要将其当作仍然有效的安全结论。
This advisory has been withdrawn because it is a duplicate of GHSA-6ww7-3frv-cqxh. This link is maintained to preserve external references.
NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that is never re-validated. An attacker can supply a validated public URL that the proxy forwards to an internal loopback-only service, allowing disclosure of internal HTTP resources, loading of forged downloader indexes, and installation of attacker-chosen package content.