Heap-Based Buffer Overflow in CTranslate2 Binary Model Loader
A heap-based buffer overflow vulnerability in the CTranslate2 binary model loader allows attackers to achieve arbitrary code execution via maliciously crafted model files.
CVE search metadata
CVE search record: CVE-2026-102566. Severity: high. CVSS: 7.8. KEV: no. Product: CTranslate2 (< 4.8.1). Brief: Heap-Based Buffer Overflow in CTranslate2 Binary Model Loader. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ctranslate2-buffer-overflow/
CTranslate2 versions prior to 4.8.1 contain a heap-based buffer overflow vulnerability residing in the binary model loader. The flaw stems from a failure to correctly validate the payload length within a model file against the allocated heap buffer size. By crafting a malicious model file with an oversized payload, an attacker can trigger an out-of-bounds write beyond the intended heap allocation boundaries. This vulnerability is critical for applications utilizing the CTranslate2 engine for model inference, as it provides a path for remote code execution or application-level denial-of-service via process crashes. Defenders should identify all environments where CTranslate2 is deployed and prioritize upgrading to version 4.8.1 or later to mitigate the risk of arbitrary code execution stemming from model ingestion.
Impact
Successful exploitation of this vulnerability allows for arbitrary code execution in the context of the process running the CTranslate2 library, or a denial-of-service condition if the overflow triggers a crash. The impact is significant for organizations performing model inference on untrusted or externally sourced machine learning models, potentially exposing the underlying host or container environment.
Recommendation
- Upgrade all instances of CTranslate2 to version 4.8.1 or later immediately.
- Implement strict source validation for all model files processed by the CTranslate2 binary loader to prevent the ingestion of untrusted or malformed binary files.
- Monitor process integrity logs for crashes associated with model loading services using CTranslate2, as these may indicate exploitation attempts.
Immediate actions
Upgrade CTranslate2 to version 4.8.1 or later.
Mitigations
Upgrade to 4.8.1 or later.
CVE-2026-102566