AINewsnow

CTranslate2 CVE-2026-102566 & CVE-2026-102567 — Heap Overflow in AI Model Loader

This story is from 2026-09-30. It is preserved in the archive; the latest stories are on the live feed.

A malicious model file is enough to corrupt memory in CTranslate2 — the inference engine behind Whisper, OpenNMT, and dozens of AI applications. Two memory-safety flaws disclosed September 29, 2026. Both affect CTranslate2 before 4.8.1. Both are fixed in 4.8.1. The CVEs CVE CVSS Type Component CVE-…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-30 01:31 · DEV Community — AI
    CTranslate2 CVE-2026-102566 & CVE-2026-102567 — Heap Overflow in AI Model Loader

More stories

  1. Best local LLM for real-time PT-BR voice conversation? (Pipeline help) — r/LocalLLM
  2. SYSTRAN's Faster Whisper Medium Transcribes 99 Languages 2.4x Faster — AlphaSignal
  3. NVIDIA Open Agent Safety Platform: A Reference for Continuous In-Silicon Agent Monitoring — NVIDIA Technical Blog
  4. Bring near-Astra intelligence to everyday work with GPT-6.1 Sol on Amazon Bedrock — AWS Machine Learning Blog
  5. The Future Is for Everyone: Muse for Small Business — Meta Newsroom
  6. How we found 24 Android vulnerabilities using our open source AI security agent — GitHub Blog
  7. Introducing Claude Sonnet 5.5 on AWS — AWS Machine Learning Blog
  8. OpenAI launches Dots, its Muse competitor — The Verge AI

Get the daily brief of stories like this at 6:30 every morning →