{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aopennmtctranslate2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:opennmt:ctranslate2:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-102566"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CTranslate2 (\u003c 4.8.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OpenNMT"],"content_html":"\u003cp\u003eCTranslate2 versions prior to 4.8.1 contain a heap-based buffer overflow vulnerability residing in the binary model loader. The flaw stems from a failure to correctly validate the payload length within a model file against the allocated heap buffer size. By crafting a malicious model file with an oversized payload, an attacker can trigger an out-of-bounds write beyond the intended heap allocation boundaries. This vulnerability is critical for applications utilizing the CTranslate2 engine for model inference, as it provides a path for remote code execution or application-level denial-of-service via process crashes. Defenders should identify all environments where CTranslate2 is deployed and prioritize upgrading to version 4.8.1 or later to mitigate the risk of arbitrary code execution stemming from model ingestion.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows for arbitrary code execution in the context of the process running the CTranslate2 library, or a denial-of-service condition if the overflow triggers a crash. The impact is significant for organizations performing model inference on untrusted or externally sourced machine learning models, potentially exposing the underlying host or container environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of CTranslate2 to version 4.8.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eImplement strict source validation for all model files processed by the CTranslate2 binary loader to prevent the ingestion of untrusted or malformed binary files.\u003c/li\u003e\n\u003cli\u003eMonitor process integrity logs for crashes associated with model loading services using CTranslate2, as these may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T16:28:39Z","date_published":"2026-09-29T16:28:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ctranslate2-buffer-overflow/","summary":"A heap-based buffer overflow vulnerability in the CTranslate2 binary model loader allows attackers to achieve arbitrary code execution via maliciously crafted model files.","title":"Heap-Based Buffer Overflow in CTranslate2 Binary Model Loader","url":"https://feed.craftedsignal.io/briefs/2026-09-ctranslate2-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:opennmt:ctranslate2:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}