A malicious model file is enough to corrupt memory in CTranslate2 — the inference
engine behind Whisper, OpenNMT, and dozens of AI applications.
Two memory-safety flaws disclosed September 29, 2026. Both affect CTranslate2 before
4.8.1. Both are fixed in 4.8.1.
| CVE | CVSS | Type | Component |
|---|---|---|---|
| CVE-2026-102566 | 7.8 | CWE-120 Heap Buffer Overflow | Binary model |
| CVE-2026-102567 | 6.1 | CWE-125 Out-of-Bounds Read | String field deserialization | CVE-2026-102566 — The binary model reads a payload length from the model
file but never validates it against the allocated heap buffer before copying. Craft a
model file with an inflated length field, write past the heap boundary, corrupt
adjacent memory structures. Arbitrary code execution.
CVE-2026-102567 — String fields in model files are deserialized without verifying
a null terminator exists. The reads past the buffer into adjacent heap memory —
crash or memory disclosure. In AI-as-a-Service deployments this could expose user data
stored nearby.
CTranslate2 powers Whisper, OpenNMT, and countless custom inference services. Model
files get pulled from Hugging Face, GitHub releases, internal registries — often
automatically in CI/CD pipelines. The attack surface is: anyone who can put a model
file in front of your inference server.
No public PoC exists yet. The attack requires only that a victim loads the malicious
file.
Upgrade to CTranslate2 4.8.1 immediately.
Until patched:
Vulnerabilities reported by Chegne Eu Joe via VulnCheck.
Full analysis with CVSS vectors, CWE classifications, and mitigation checklist:
[CTranslate2 CVE-2026-102566 & CVE-2026-102567](https://threataft.com/articles/ctranslate2-cve-2026-102566-102567-model-)
*Originally published at [ThreatAft](https://threataft.com)*