This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-12243 as REJECTED on . There is no longer a valid blast radius to assess. Any historical package or vendor data shown below is preserved for audit reference only.
Reason given by MITRE
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-12243 Blast Radius
✕ WITHDRAWN — HISTORICAL DATANLTK version 3.9.4 is vulnerable to a path traversal attack due to an incomplete fix for GitHub Issue #3504. The `_UNSAFE_NO_PROTOCOL_RE` regex in `nl…