Loading market data...
← Back to CVE feed

CVE-2026-102567

MEDIUM CVSS 6.1 View on NVD ↗

Description

CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Published: Sep 29, 2026 15:17 UTC Modified: Sep 29, 2026 15:17 UTC