CVE-2026-102566
Received Received - Intake

Heap-based Buffer Overflow in CTranslate2

Vulnerability report for CVE-2026-102566, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
opennmt ctranslate2 to 4.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-102566 is a heap-based buffer overflow in CTranslate2 versions before 4.8.1. The vulnerability occurs in the binary model loader where payload length is not validated against the allocated buffer size. Attackers can exploit this by creating malicious model files with oversized payloads, causing memory corruption that may lead to crashes or arbitrary code execution.

Detection Guidance

To detect this vulnerability, check the installed version of CTranslate2. Run: pip show ctranslate2. If the version is below 4.8.1, the system is vulnerable. Additionally, inspect model files for unusual payload lengths or corrupted data during loading.

Impact Analysis

If you use CTranslate2 versions prior to 4.8.1, this vulnerability could allow attackers to execute arbitrary code on your system or cause crashes by exploiting heap memory corruption. This is particularly risky if you load untrusted model files, as attackers could craft malicious files to trigger the overflow.

Mitigation Strategies

Upgrade CTranslate2 to version 4.8.1 or later immediately. Use: pip install --upgrade ctranslate2. Remove any untrusted model files and validate new models before loading. Monitor systems for crashes or unusual behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102566. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart