CVE-2026-102567: Out-of-bounds Read in OpenNMT CTranslate2
CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.
AI Analysis
Technical Summary
CVE-2026-102567 is an out-of-bounds heap read vulnerability in OpenNMT's CTranslate2 library prior to version 4.8.1. The issue arises in the binary model loader component when it deserializes string fields without null terminators, enabling attackers to craft malicious model files that trigger reads past the allocated buffer. This can result in crashes or unintended disclosure of heap memory adjacent to the buffer.
Potential Impact
Successful exploitation can cause the application using CTranslate2 to crash or leak adjacent heap memory contents. This may lead to denial of service or information disclosure, but no evidence of privilege escalation or remote code execution is indicated.
Mitigation Recommendations
Upgrade to CTranslate2 version 4.8.1 or later, where this vulnerability has been fixed. No other mitigation guidance is provided.
CVE-2026-102567: Out-of-bounds Read in OpenNMT CTranslate2
Description
CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.
CVSS v4.0
Score 6.9medium
Affected software
OpenNMT
CTranslate2
pkg:github/opennmt/CTranslate2Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-102567 is an out-of-bounds heap read vulnerability in OpenNMT's CTranslate2 library prior to version 4.8.1. The issue arises in the binary model loader component when it deserializes string fields without null terminators, enabling attackers to craft malicious model files that trigger reads past the allocated buffer. This can result in crashes or unintended disclosure of heap memory adjacent to the buffer.
Potential Impact
Successful exploitation can cause the application using CTranslate2 to crash or leak adjacent heap memory contents. This may lead to denial of service or information disclosure, but no evidence of privilege escalation or remote code execution is indicated.
Mitigation Recommendations
Upgrade to CTranslate2 version 4.8.1 or later, where this vulnerability has been fixed. No other mitigation guidance is provided.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-29T13:43:14.954Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abbcfbdf7a7c5410683e20c
Added to database: 09/29/2026, 14:48:30 UTC
Last enriched: 09/29/2026, 15:03:02 UTC
Last updated: 09/29/2026, 16:34:22 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.