CVE-2026-102567

Source
https://cve.org/CVERecord?id=CVE-2026-102567
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102567.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-102567
Published
2026-09-29T14:22:36Z
Modified
2026-10-02T08:13:48Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
CTranslate2 before 4.8.1 Out-of-Bounds Read via Model Deserialization
Details

CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-125"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102567.json"
}
References

Affected packages

Git / github.com/opennmt/ctranslate2

Affected ranges

Type
GIT
Repo
https://github.com/opennmt/ctranslate2
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "CTranslate2"
        },
        {
            "fixed":  "4.8.1"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

Other
benchmark-10
benchmark-11
benchmark-2
benchmark-3
benchmark-4
benchmark-5
benchmark-6
benchmark-7
benchmark-8
benchmark-9
v0.*
v0.1.0
v0.1.1
v0.10.0
v0.10.1
v0.10.2
v0.11.0
v0.12.0
v0.13.0
v0.14.0
v0.15.0
v0.15.1
v0.16.0
v0.16.1
v0.16.2
v0.16.3
v0.16.4
v0.17.0
v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4
v0.6.0
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.8.0
v0.8.1
v0.9.0
v1.*
v1.0.0
v1.0.1
v1.1.0
v1.10.0
v1.10.1
v1.11.0
v1.12.0
v1.12.1
v1.13.0
v1.13.1
v1.13.2
v1.14.0
v1.15.0
v1.16.0
v1.16.1
v1.16.2
v1.17.0
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.20.0
v1.20.1
v1.3.0
v1.4.0
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.7.0
v1.8.0
v1.9.0
v2.*
v2.0.0
v2.1.0
v2.10.0
v2.10.1
v2.11.0
v2.12.0
v2.13.0
v2.13.1
v2.14.0
v2.15.0
v2.15.1
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.1
v2.2.0
v2.20.0
v2.21.0
v2.21.1
v2.22.0
v2.23.0
v2.24.0
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v2.5.1
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.9.0
v3.*
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.10.0
v3.10.1
v3.10.2
v3.11.0
v3.12.0
v3.13.0
v3.14.0
v3.15.0
v3.15.1
v3.16.0
v3.16.1
v3.17.0
v3.17.1
v3.18.0
v3.19.0
v3.2.0
v3.20.0
v3.21.0
v3.22.0
v3.23.0
v3.24.0
v3.3.0
v3.4.0
v3.5.0
v3.5.1
v3.6.0
v3.7.0
v3.8.0
v3.9.0
v3.9.1
v4.*
v4.0.0
v4.1.0
v4.1.1
v4.2.0
v4.2.1
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102567.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "307562268922336013914666342860461343631",
                "48845529637832835849491722408424802416",
                "83444293469545751576379700348391994211",
                "320818270232960460214132254547492069980",
                "118718591396755968019450204669189703969",
                "146584550292134290719659391887242882934",
                "339696330661559358842315927006701084141",
                "326240358643305475389916223762723824253",
                "127520982562202079632111015330310191532",
                "134143038399780389623385288077077572352"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-102567-74bf27f1",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/opennmt/ctranslate2/commit/d9b991e0700933a0c05373df8b52ed89cdcab96d",
        "target":  {
            "file":  "src/models/model.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "156441760499938916599138257738475579",
            "length":  5839
        },
        "id":  "CVE-2026-102567-fba4765b",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/opennmt/ctranslate2/commit/d9b991e0700933a0c05373df8b52ed89cdcab96d",
        "target":  {
            "file":  "src/models/model.cc",
            "function":  "Model::load"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "180858100638785783307188328568286389415",
            "length":  205
        },
        "id":  "CVE-2026-102567-fc9a4305",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/opennmt/ctranslate2/commit/d9b991e0700933a0c05373df8b52ed89cdcab96d",
        "target":  {
            "file":  "src/models/model.cc",
            "function":  "consume"
        }
    }
]
vanir_signatures_modified
"2026-10-02T08:13:48Z"