High severity7.8OSV Advisory· Published Jan 22, 2026· Updated Jul 15, 2026
CVE-2026-1260
CVE-2026-1260
Description
Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sentencepiecePyPI | < 0.2.1 | 0.2.1 |
Affected products
40.2.1pre1, v0.1.4, v0.1.5, …+ 1 more
- (no CPE)range: 0.2.1pre1, v0.1.4, v0.1.5, …
- cpe:2.3:a:google:sentencepiece:*:*:*:*:*:*:*:*range: <0.2.1
- ghsa-coords2 versions
< 0.2.1+ 1 more
- (no CPE)range: < 0.2.1
- (no CPE)range: < 3.3.7-r6
Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-38vq-g6vr-w8wfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-1260ghsaADVISORY
- github.com/google/sentencepiece/commit/d856b67fdb3492e035489abf9b3aaf486144b2c0ghsaWEB
- github.com/google/sentencepiece/releases/tag/v0.2.1nvdProductRelease NotesWEB
- access.redhat.com/errata/RHSA-2026:3713nvd
- access.redhat.com/errata/RHSA-2026:3782nvd
- access.redhat.com/security/cve/CVE-2026-1260nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1260.jsonnvd
News mentions
0No linked articles in our index yet.