openSUSE has issued an advisory on April 1: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/Z36Q44HZY76RE7YZX5B55777UQB6MPEI/
Source RPM: (none) => python-nltk-3.9.3-1.mga10.src.rpm, python-nltk-3.9.3-1.mga9.src.rpmCVE: (none) => CVE-2026-33230Whiteboard: (none) => MGA9TOOFlags: (none) => affects_mga9+Status comment: (none) => Fixed upstream in 3.9.4
For Cauldron, I asked for a freeze move. Suggested advisory: ======================== The updated package fixes a security vulnerability: nltk Vulnerable to Cross-site Scripting. (CVE-2026-33230) References: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/Z36Q44HZY76RE7YZX5B55777UQB6MPEI/ ======================== Updated package in core/updates_testing: ======================== python3-nltk-3.9.4-1.mga9 from SRPM: python-nltk-3.9.4-1.mga9.src.rpm
Status: NEW => ASSIGNEDStatus comment: Fixed upstream in 3.9.4 => (none)Whiteboard: MGA9TOO => (none)Version: Cauldron => 9Flags: affects_mga9+ => (none)Assignee: bugsquad => qa-bugsSource RPM: python-nltk-3.9.3-1.mga10.src.rpm, python-nltk-3.9.3-1.mga9.src.rpm => python-nltk-3.9.3-1.mga9.src.rpm
Keywords: (none) => advisory
MGA9-64 server Plasma Wayland on Compaq H000SB. No installation issues. Ref bug 30604, so OK on clean install.
Whiteboard: (none) => MGA9-64-OKFlags: (none) => test_passed_mga9_64+CC: (none) => herman.viaene
Validating.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2026-0082.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED