CTranslate2 CVE-2026-102566 & CVE-2026-102567 — Heap Overflow in AI Model Loader
This story is from 2026-09-30. It is preserved in the archive; the latest stories are on the live feed.
A malicious model file is enough to corrupt memory in CTranslate2 — the inference engine behind Whisper, OpenNMT, and dozens of AI applications. Two memory-safety flaws disclosed September 29, 2026. Both affect CTranslate2 before 4.8.1. Both are fixed in 4.8.1. The CVEs CVE CVSS Type Component CVE-…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-30 01:31 · DEV Community — AI
CTranslate2 CVE-2026-102566 & CVE-2026-102567 — Heap Overflow in AI Model Loader