CVE-2026-102566: CTranslate2 before 4.8.1 Heap Buffer Overflow via model.bin

Published Sep 29, 2026
·
Updated

CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.

Affected Software

1 affected component
OpenNMT CTranslate2<4.8.1

Event History

Sep 29, 2026
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using CTranslate2 versions before 4.8.1 are exposed when they load binary model files. The issue is in the binary model loader and is triggered by a malicious model.bin payload.

2

What does an attacker need to exploit this issue?

An attacker needs to provide a crafted model file with an oversized payload length and have it loaded by the affected software. The vector is local, requires no privileges, and requires user interaction.

3

What should teams do if they cannot update immediately?

Avoid loading model files from untrusted sources until CTranslate2 can be updated to 4.8.1 or later. Restrict model loading to known, trusted model artifacts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203