Medium severity6.1NVD Advisory· Published Sep 29, 2026
CVE-2026-102567
CVE-2026-102567
Description
CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.8.1
Patches
Vulnerability mechanics
References
5- github.com/OpenNMT/CTranslate2/blob/v4.8.0/src/models/model.ccnvd
- github.com/OpenNMT/CTranslate2/commit/d9b991e0700933a0c05373df8b52ed89cdcab96dnvd
- github.com/OpenNMT/CTranslate2/pull/2068nvd
- github.com/OpenNMT/CTranslate2/releases/tag/v4.8.1nvd
- www.vulncheck.com/advisories/ctranslate2-before-4.8.1-out-of-bounds-read-via-model-deserializationnvd
News mentions
0No linked articles in our index yet.