OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-102566 (CVSS 8.5)

NVD · officialPublished Sep 29, 2026Risk 37/100

CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.

CVSS
8.5
AV:LocalAC:LowPR:NoneUI:Passive

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source