---
id: CVE-2026-102566
title: >-
  CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary
  model loader that fails to validate payload length against allocated buffer
  size
summary: >-
  CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary
  model loader that fails to validate payload length against allocated buffer
  size. Attackers can craft malicious model files with oversized payload lengths
  to wr…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: OpenNMT
product: CTranslate2
affected:
  - CTranslate2 < 4.8.1
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T15:17:18.003'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102566'
references:
  - url: 'https://github.com/OpenNMT/CTranslate2'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/OpenNMT/CTranslate2/blob/v4.8.0/src/models/model.cc#L656-L657
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/OpenNMT/CTranslate2/commit/d9b991e0700933a0c05373df8b52ed89cdcab96d
    label: disclosure@vulncheck.com
  - url: 'https://github.com/OpenNMT/CTranslate2/pull/2068'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/OpenNMT/CTranslate2/releases/tag/v4.8.1'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ctranslate2-before-4.8.1-heap-buffer-overflow-via-model-bin
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-29T14:48:31.801016Z'
ingestedAt: '2026-09-29T16:39:33.257Z'
---

## Overview

CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
