CVE-2026-102566 PUBLISHED

CTranslate2 before 4.8.1 Heap Buffer Overflow via model.bin

Assigner: VulnCheck
Reserved: 29.09.2026 Published: 29.09.2026 Updated: 29.09.2026

CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor OpenNMT
Product CTranslate2
Versions Default: unaffected
  • affected from 0 to 4.8.1 (excl.)
  • Version 4.8.1 is unaffected

Credits

  • Chegne Eu Joe finder

References

Problem Types

  • Out-of-bounds Write CWE