CVE-2026-102567: CTranslate2 before 4.8.1 Out-of-Bounds Read via Model Deserialization
Published Sep 29, 2026
·Updated
CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.
Affected Software
1 affected component
OpenNMT CTranslate2<4.8.1
Event History
Sep 29, 2026
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker be able to do to exploit this issue?
An attacker needs to provide or induce use of a crafted binary model file. The vulnerable code is reached when CTranslate2 deserializes string fields in that model.
2
What impact can a malicious model file have?
A crafted model can cause reads beyond heap-buffer boundaries. This can crash the process or disclose adjacent heap memory contents.
3
Which versions need to be remediated?
CTranslate2 versions before 4.8.1 are affected. Upgrade to 4.8.1 or later.