CVE-2026-102567 PUBLISHED

CTranslate2 before 4.8.1 Out-of-Bounds Read via Model Deserialization

Assigner: VulnCheck
Reserved: 29.09.2026 Published: 29.09.2026 Updated: 29.09.2026

CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor OpenNMT
Product CTranslate2
Versions Default: unaffected
  • affected from 0 to 4.8.1 (excl.)
  • Version 4.8.1 is unaffected

Credits

  • Chegne Eu Joe finder

References

Problem Types

  • Out-of-bounds Read CWE