CVE-2026-102567
6.1 MEDIUMpublic exploit availablePublished 2026-09-29 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Weaknesses
CWE-125
Public exploit & PoC references
- https://github.com/OpenNMT/CTranslate2
- https://github.com/OpenNMT/CTranslate2/blob/v4.8.0/src/models/model.cc#L81-L87
- https://github.com/OpenNMT/CTranslate2/commit/d9b991e0700933a0c05373df8b52ed89cdcab96d
- https://github.com/OpenNMT/CTranslate2/pull/2068
- https://github.com/OpenNMT/CTranslate2/releases/tag/v4.8.1
All references
- https://github.com/OpenNMT/CTranslate2
- https://github.com/OpenNMT/CTranslate2/blob/v4.8.0/src/models/model.cc#L81-L87
- https://github.com/OpenNMT/CTranslate2/commit/d9b991e0700933a0c05373df8b52ed89cdcab96d
- https://github.com/OpenNMT/CTranslate2/pull/2068
- https://github.com/OpenNMT/CTranslate2/releases/tag/v4.8.1
- https://www.vulncheck.com/advisories/ctranslate2-before-4.8.1-out-of-bounds-read-via-model-deserialization
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100387PoC
- MEDIUMCVE-2026-100505PoC
- MEDIUMCVE-2026-101204
- MEDIUMCVE-2026-101205
- MEDIUMCVE-2026-102318
- HIGHCVE-2026-102360PoC
- MEDIUMCVE-2026-102507PoC
- HIGHCVE-2026-102521PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.