MEDIUM 6.9 NVD
CVE-2026-102567
CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators.
CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.
References
- https://github.com/OpenNMT/CTranslate2
- https://github.com/OpenNMT/CTranslate2/blob/v4.8.0/src/models/model.cc#L81-L87
- https://github.com/OpenNMT/CTranslate2/commit/d9b991e0700933a0c05373df8b52ed89cdcab96d
- https://github.com/OpenNMT/CTranslate2/pull/2068
- https://github.com/OpenNMT/CTranslate2/releases/tag/v4.8.1
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-09-29 via NVD.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.