Sceawere

Vulnerability Detail

CVE-2026-102566UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CTranslate2 Heap Buffer Overflow

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
10h ago
Vendor
OpenNMT
Product
CTranslate2
Attack Type
Out-of-bounds Write
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-09-29T15:17:18.003Z",
  "pubdate": "2026-09-29T15:17:18.003Z",
  "executiveSummary": "CTranslate2 versions prior to 4.8.1 are susceptible to a heap-based buffer overflow vulnerability residing within the binary model loader component.\nThe vulnerability stems from improper validation of payload lengths during the parsing of model files, allowing an attacker to supply a crafted file that exceeds the bounds of the pre-allocated heap memory.\nSuccessful exploitation of this flaw can result in a denial-of-service condition due to memory corruption, leading to application crashes, or potentially permit arbitrary code execution under the security context of the process.\nThe vulnerability is triggered when the application processes a maliciously crafted model file. As the software does not adequately verify the relationship between the data payload length and the designated heap buffer size, memory corruption occurs during data ingestion.\nThis represents a significant security risk for any environment relying on CTranslate2 for model deployment, particularly in multi-tenant or untrusted input scenarios, as it allows attackers to bypass boundary checks through manipulated model artifacts.\nNo specific authentication is mentioned as a prerequisite, suggesting that any process capable of loading a model file into the CTranslate2 engine could potentially trigger the exploit.",
  "technicalDetails": "The vulnerability is classified as a heap-based buffer overflow occurring within the binary model loading logic of CTranslate2. The root cause is a deficiency in input sanitization and boundary checking within the parser responsible for reading binary model representations from disk.\nDuring the initialization of the model loading routine, the library allocates a fixed-size buffer on the heap intended to accommodate incoming model data structures. The loader reads metadata from the provided model file, which includes length indicators for subsequent payloads or data chunks. The parser fails to perform a comparison check between the declared payload length field in the file header and the actual allocated size of the destination buffer.\nIn a typical attack flow, an attacker creates a malicious model file with an engineered header that specifies a payload size significantly larger than the target heap buffer. When the CTranslate2 binary loader parses this file, it utilizes the user-supplied length value to control a 'memcpy' or similar block-write operation. Because the size validation is absent, the memory management subsystem permits the copy operation to proceed beyond the defined boundary of the heap chunk.\nThis leads to the overwriting of adjacent memory chunks on the heap. Depending on the memory layout at the time of execution, an attacker may overwrite critical heap metadata, function pointers, or object pointers. If an attacker can precisely control the content written beyond the buffer, they may overwrite a return address or a function pointer, redirected the execution flow to an attacker-controlled memory address (e.g., shellcode stored in the heap) once the affected function returns or the corrupted pointer is accessed.\nThe exploitation process does not require high-level privileges; it relies on the execution of the loader code with the permissions of the application process itself. The risk is elevated in applications that automatically pull or process models from external or user-accessible sources. If the heap layout is predictable, the attacker can achieve reliable arbitrary code execution. If not, the corruption of critical metadata almost invariably results in a SIGSEGV or similar memory protection fault, leading to an immediate process crash and denial of service.\nAffected versions include all releases of CTranslate2 prior to 4.8.1. The vulnerability is triggered during the standard model loading lifecycle, effectively placing the attack surface on the file parsing component of the library."
}
CVE-2026-102566: CTranslate2 Heap Buffer Overflow (HIGH Severity, CVSS: 7.8) | Sceawere