OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102566

HIGH · CVSS 7.8 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

CTranslate2 versions prior to 4.8.1 are susceptible to a heap-based buffer overflow in the binary model loader due to inadequate validation of payload lengths against allocated buffer sizes. This vulnerability allows attackers to create malicious model files that can lead to crashes or arbitrary code execution. Organizations utilizing CTranslate2 should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102566
Severity
HIGH
CVSS
7.8
EPSS
0.15%

Original NVD Description

CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.