CTranslate2 CVE-2026-102566 & CVE-2026-102567: Heap Overflow in AI Model Loader
Two memory-safety flaws were disclosed in CTranslate2, the inference engine behind Whisper and OpenNMT: a heap buffer overflow (CVE-2026-102566, CVSS 7.8) and an out-of-bounds read (CVE-2026-102567, CVSS 6.1). Both affect versions before 4.8.1, which contains the fix.
- CVE-2026-102566: CVSS 7.8 heap overflow in the binary model loader
- CVE-2026-102567: CVSS 6.1 out-of-bounds read in string deserialization
- All CTranslate2 versions before 4.8.1 are affected; fix released September 29, 2026
- No public PoC yet, but loading a malicious model file is enough to trigger it
Read next
Software