High severity7.8NVD Advisory· Published Sep 16, 2026
CVE-2026-92786
CVE-2026-92786
Description
LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_ buffer during feature contribution computation.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=4.7.0
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.