---
id: CVE-2026-1260
title: >-
  Invalid memory access in Sentencepiece versions less than 0.2.1 when using a
  vulnerable model file, which is not created in the normal training procedure.
summary: >-
  Invalid memory access in Sentencepiece versions less than 0.2.1 when using a
  vulnerable model file, which is not created in the normal training procedure.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
vendor: google
product: sentencepiece
affected:
  - sentencepiece < 0.2.1
patched:
  - sentencepiece 0.2.1
published: '2026-01-22'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1260'
references:
  - url: 'https://github.com/google/sentencepiece/releases/tag/v0.2.1'
    label: cve-coordination@google.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:3713'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:3782'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-1260'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2432079'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1260.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1260'
  - url: >-
      https://github.com/google/sentencepiece/commit/d856b67fdb3492e035489abf9b3aaf486144b2c0
  - url: 'https://github.com/google/sentencepiece'
tags:
  - nvd
  - osv
  - pip
epss: 0.00178
epssPercentile: 0.06523
ingestedAt: '2026-06-30T13:26:50.541Z'
aliases:
  - GHSA-38vq-g6vr-w8wf
  - PYSEC-2026-1909
ecosystem: pip
---

## Overview

Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.

## Affected

- `sentencepiece < 0.2.1`

## Remediation

Upgrade past the affected range:

- `sentencepiece 0.2.1`

## Package advisory (CVE-2026-1260)

Affected packages:

- `sentencepiece < 0.2.1`

Patched in:

- `sentencepiece 0.2.1`

Source: https://osv.dev/vulnerability/GHSA-38vq-g6vr-w8wf
