Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opennmt
Opennmt ctranslate2 |
|
| Vendors & Products |
Opennmt
Opennmt ctranslate2 |
Tue, 29 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution. | |
| Title | CTranslate2 before 4.8.1 Heap Buffer Overflow via model.bin | |
| Weaknesses | CWE-787 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T14:49:12.947Z
Reserved: 2026-09-29T13:43:06.440Z
Link: CVE-2026-102566
Updated: 2026-09-29T14:48:54.191Z
Status : Awaiting Analysis
Published: 2026-09-29T15:17:18.003
Modified: 2026-09-30T17:23:08.953
Link: CVE-2026-102566
No data.
OpenCVE Enrichment
Updated: 2026-09-30T20:41:55Z
-
CWE-787
Out-of-bounds Write