---
id: CVE-2026-73066
title: Tesseract is an open source OCR engine
summary: >-
  Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata
  LSTM model component loaded through Tesseract's deserializer can cause an
  unchecked signed integer multiplication in Convolve::DeSerialize in
  src/lstm/convolv…
severity: high
cwe:
  - CWE-787
published: '2026-08-11'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:46:02.457'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73066'
references:
  - url: >-
      https://github.com/tesseract-ocr/tesseract/commit/2f4d2f4bf45c363785d7bf1da29b6628f8939a72
    label: security-advisories@github.com
  - url: 'https://github.com/tesseract-ocr/tesseract/pull/4588'
    label: security-advisories@github.com
  - url: 'https://github.com/tesseract-ocr/tesseract/releases/tag/5.5.3'
    label: security-advisories@github.com
  - url: >-
      https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-7j76-5rq5-5jg8
    label: security-advisories@github.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73066.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-73066'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2514011'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-73066'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73066'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67830'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67832'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67831'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69111'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69495'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71566'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71568'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71567'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.00182
epssPercentile: 0.06912
ingestedAt: '2026-09-09T21:22:45.527Z'
vendor: Red Hat
product: Red Hat Enterprise Linux AppStream (v. 9)
affected:
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_v_9
  - enterprise_linux_codeready_linux_builder_v_10
  - enterprise_linux_crb_v_8
  - enterprise_linux_codeready_linux_builder_v_9
patched:
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_v_9
  - enterprise_linux_codeready_linux_builder_v_10
  - enterprise_linux_crb_v_8
  - enterprise_linux_codeready_linux_builder_v_9
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'
cvssSource: vendor
---

## Overview

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:67830** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67830)
- **RHSA-2026:67832** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67832)
- **RHSA-2026:67831** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67831)
- **RHSA-2026:69111** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69111)
- **RHSA-2026:69495** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69495)
- **RHSA-2026:71566** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71566)
- **RHSA-2026:71568** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71568)
- **RHSA-2026:71567** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat CodeReady Linux Builder EUS (v.9.6) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71567)
