{"slug": "ctranslate2-cve-2026-102566-cve-2026-102567-heap-overflow-in-ai-model-loader", "title": "CTranslate2 CVE-2026-102566 & CVE-2026-102567 — Heap Overflow in AI Model Loader", "summary": "Two memory-safety vulnerabilities in CTranslate2, the inference engine behind Whisper and OpenNMT, were disclosed on September 29, 2026, and fixed in version 4.8.1. CVE-2026-102566 (CVSS 7.8) is a heap buffer overflow in the binary model loader that can lead to arbitrary code execution, while CVE-2026-102567 (CVSS 6.1) is an out-of-bounds read during string field deserialization that can crash the loader or disclose adjacent heap memory, potentially exposing user data in AI-as-a-Service deployments. Both flaws require only that a victim load a malicious model file, and the vulnerabilities were reported by Chegne Eu Joe via VulnCheck.", "body_md": "A malicious model file is enough to corrupt memory in CTranslate2 — the inference \n\nengine behind Whisper, OpenNMT, and dozens of AI applications.\n\nTwo memory-safety flaws disclosed September 29, 2026. Both affect CTranslate2 before \n\n4.8.1. Both are fixed in 4.8.1.\n\n| CVE | CVSS | Type | Component | \n|---|---|---|---|\n| CVE-2026-102566 | **7.8** | CWE-120 Heap Buffer Overflow | Binary model loader | \n| CVE-2026-102567 | **6.1** | CWE-125 Out-of-Bounds Read | String field deserialization | \n\n**CVE-2026-102566** — The binary model loader reads a payload length from the model \n\nfile but never validates it against the allocated heap buffer before copying. Craft a \n\nmodel file with an inflated length field, write past the heap boundary, corrupt \n\nadjacent memory structures. Arbitrary code execution.\n\n**CVE-2026-102567** — String fields in model files are deserialized without verifying \n\na null terminator exists. The loader reads past the buffer into adjacent heap memory — \n\ncrash or memory disclosure. In AI-as-a-Service deployments this could expose user data \n\nstored nearby.\n\nCTranslate2 powers Whisper, OpenNMT, and countless custom inference services. Model \n\nfiles get pulled from Hugging Face, GitHub releases, internal registries — often \n\nautomatically in CI/CD pipelines. The attack surface is: anyone who can put a model \n\nfile in front of your inference server.\n\nNo public PoC exists yet. The attack requires only that a victim loads the malicious \n\nfile.\n\nUpgrade to **CTranslate2 4.8.1** immediately.\n\nUntil patched:\n\nVulnerabilities reported by Chegne Eu Joe via VulnCheck.\n\n*Full analysis with CVSS vectors, CWE classifications, and mitigation checklist:*\n\n[CTranslate2 CVE-2026-102566 & CVE-2026-102567](https://threataft.com/articles/ctranslate2-cve-2026-102566-102567-model-loader)\n\n*Originally published at [ThreatAft](https://threataft.com)*", "url": "https://wpnews.pro/news/ctranslate2-cve-2026-102566-cve-2026-102567-heap-overflow-in-ai-model-loader", "canonical_source": "https://dev.to/threataft_dev/ctranslate2-cve-2026-102566-cve-2026-102567-heap-overflow-in-ai-model-loader-552n", "published_at": "2026-09-30 01:31:21+00:00", "updated_at": "2026-09-30 01:46:42.001611+00:00", "lang": "en", "topics": ["ai-infrastructure", "ai-safety", "mlops", "ai-tools"], "entities": ["CTranslate2", "Whisper", "OpenNMT", "Hugging Face", "VulnCheck", "Chegne Eu Joe", "ThreatAft"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/ctranslate2-cve-2026-102566-cve-2026-102567-heap-overflow-in-ai-model-loader", "markdown": "https://wpnews.pro/news/ctranslate2-cve-2026-102566-cve-2026-102567-heap-overflow-in-ai-model-loader.md", "text": "https://wpnews.pro/news/ctranslate2-cve-2026-102566-cve-2026-102567-heap-overflow-in-ai-model-loader.txt", "jsonld": "https://wpnews.pro/news/ctranslate2-cve-2026-102566-cve-2026-102567-heap-overflow-in-ai-model-loader.jsonld"}}