---
id: CVE-2026-102567
title: >-
  CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in
  the binary model loader when deserializing string fields without null
  terminators
summary: >-
  CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in
  the binary model loader when deserializing string fields without null
  terminators. Attackers can craft malicious model files to trigger heap memory
  reads past …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'
cwe:
  - CWE-125
vendor: OpenNMT
product: CTranslate2
affected:
  - CTranslate2 < 4.8.1
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T15:17:18.177'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102567'
references:
  - url: 'https://github.com/OpenNMT/CTranslate2'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/OpenNMT/CTranslate2/blob/v4.8.0/src/models/model.cc#L81-L87
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/OpenNMT/CTranslate2/commit/d9b991e0700933a0c05373df8b52ed89cdcab96d
    label: disclosure@vulncheck.com
  - url: 'https://github.com/OpenNMT/CTranslate2/pull/2068'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/OpenNMT/CTranslate2/releases/tag/v4.8.1'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ctranslate2-before-4.8.1-out-of-bounds-read-via-model-deserialization
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-29T14:57:23.531287Z'
ingestedAt: '2026-09-29T16:39:33.257Z'
---

## Overview

CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
