CVE-2026-102567
Received Received - Intake

Out-of-Bounds Heap Read in CTranslate2

Vulnerability report for CVE-2026-102567, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
opennmt ctranslate2 to 4.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-102567 is an out-of-bounds heap read vulnerability in CTranslate2 versions before 4.8.1. It occurs during the deserialization of string fields in binary model files that lack null terminators. Attackers can exploit this by creating malicious model files to read beyond allocated memory, potentially causing crashes or leaking sensitive heap data.

Detection Guidance

Detection involves checking for crashes or memory disclosures when loading binary model files with CTranslate2 versions before 4.8.1. Monitor application logs for segmentation faults or heap corruption errors during model loading. Test suspicious model files in a controlled environment to observe abnormal behavior.

Impact Analysis

This vulnerability may allow attackers to crash applications using CTranslate2 or access sensitive memory contents. If exploited, it could lead to information disclosure, denial-of-service, or further exploitation depending on the application's context and data processed.

Mitigation Strategies

Upgrade CTranslate2 to version 4.8.1 or later immediately. If upgrading is not possible, avoid loading untrusted binary model files. Implement strict input validation for model files and restrict access to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102567. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart