cd /news/ai-infrastructure/ctranslate2-cve-2026-102566-cve-2026… · home › topics › ai-infrastructure › article
[ARTICLE · art-142165] src=dev.to ↗ pub= topic=ai-infrastructure verified=true sentiment=↓ negative

CTranslate2 CVE-2026-102566 & CVE-2026-102567 — Heap Overflow in AI Model Loader

Two memory-safety vulnerabilities in CTranslate2, the inference engine behind Whisper and OpenNMT, were disclosed on September 29, 2026, and fixed in version 4.8.1. CVE-2026-102566 (CVSS 7.8) is a heap buffer overflow in the binary model loader that can lead to arbitrary code execution, while CVE-2026-102567 (CVSS 6.1) is an out-of-bounds read during string field deserialization that can crash the loader or disclose adjacent heap memory, potentially exposing user data in AI-as-a-Service deployments. Both flaws require only that a victim load a malicious model file, and the vulnerabilities were reported by Chegne Eu Joe via VulnCheck.

by read1 min views1 publishedSep 30, 2026

A malicious model file is enough to corrupt memory in CTranslate2 — the inference

engine behind Whisper, OpenNMT, and dozens of AI applications.

Two memory-safety flaws disclosed September 29, 2026. Both affect CTranslate2 before

4.8.1. Both are fixed in 4.8.1.

CVE CVSS Type Component
CVE-2026-102566 7.8 CWE-120 Heap Buffer Overflow Binary model

| CVE-2026-102567 | 6.1 | CWE-125 Out-of-Bounds Read | String field deserialization | CVE-2026-102566 — The binary model reads a payload length from the model

file but never validates it against the allocated heap buffer before copying. Craft a

model file with an inflated length field, write past the heap boundary, corrupt

adjacent memory structures. Arbitrary code execution.

CVE-2026-102567 — String fields in model files are deserialized without verifying

a null terminator exists. The reads past the buffer into adjacent heap memory —

crash or memory disclosure. In AI-as-a-Service deployments this could expose user data

stored nearby.

CTranslate2 powers Whisper, OpenNMT, and countless custom inference services. Model

files get pulled from Hugging Face, GitHub releases, internal registries — often

automatically in CI/CD pipelines. The attack surface is: anyone who can put a model

file in front of your inference server.

No public PoC exists yet. The attack requires only that a victim loads the malicious

file.

Upgrade to CTranslate2 4.8.1 immediately.

Until patched:

Vulnerabilities reported by Chegne Eu Joe via VulnCheck.

Full analysis with CVSS vectors, CWE classifications, and mitigation checklist:

[CTranslate2 CVE-2026-102566 & CVE-2026-102567](https://threataft.com/articles/ctranslate2-cve-2026-102566-102567-model-)

*Originally published at [ThreatAft](https://threataft.com)*
── more in #ai-infrastructure 4 stories · sorted by recency
── more on @ctranslate2 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ctranslate2-cve-2026…] indexed:0 read:1min 2026-09-30 · —