CVE-2026-102567: Opennmt CTRANSLATE2

Medium severity, CVSS 6.1. EPSS: 0.1% chance of exploitation in the next 30 days.

CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.

Affected products

  • Opennmt CTRANSLATE2: before 4.8.1 (fixed in 4.8.1)

Published 2026-09-29. Last modified 2026-09-30.