CTranslate2 CVE-2026-102566 & CVE-2026-102567 — Heap Overflow in AI Model Loader
A malicious model file is enough to corrupt memory in CTranslate2 — the inference engine behind Whisper, OpenNMT, and dozens of AI applications. Two memory-safety flaws disclosed September 29, 2026. Both affect CTransl
A malicious model file is enough to corrupt memory in CTranslate2 — the inference
engine behind Whisper, OpenNMT, and dozens of AI applications.
Two memory-safety flaws disclosed September 29, 2026. Both affect CTranslate2 before
4.8.1. Both are fixed in 4.8.1.
The CVEs
| CVE | CVSS | Type | Component |
|---|---|---|---|
| CVE-2026-102566 | 7.8 | CWE-120 Heap Buffer Overflow | Binary model loader |
| CVE-2026-102567 | 6.1 | CWE-125 Out-of-Bounds Read | String field deserialization |
What happened
CVE-2026-102566 — The binary model loader reads a payload length from the model
file but never validates it against the allocated heap buffer before copying. Craft a
model file with an inflated length field, write past the heap boundary, corrupt
adjacent memory structures. Arbitrary code execution.
CVE-2026-102567 — String fields in model files are deserialized without verifying
a null terminator exists. The loader reads past the buffer into adjacent heap memory —
crash or memory disclosure. In AI-as-a-Service deployments this could expose user data
stored nearby.
Why AI pipelines are exposed
CTranslate2 powers Whisper, OpenNMT, and countless custom inference services. Model
files get pulled from Hugging Face, GitHub releases, internal registries — often
automatically in CI/CD pipelines. The attack surface is: anyone who can put a model
file in front of your inference server.
No public PoC exists yet. The attack requires only that a victim loads the malicious
file.
Fix
Upgrade to CTranslate2 4.8.1 immediately.
Until patched:
- Restrict model loading to trusted, verified sources
- Validate checksums before loading model files
- Audit any pipeline that ingests third-party models
- Restrict who can upload to model endpoints
Vulnerabilities reported by Chegne Eu Joe via VulnCheck.
Full analysis with CVSS vectors, CWE classifications, and mitigation checklist:
CTranslate2 CVE-2026-102566 & CVE-2026-102567
Originally published at ThreatAft
Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.