Skip to main content
HIGH

CVE-2026-102566

CVSS v3

7.8

HIGH

EPSS Score

—

exploit probability

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.

Technical details

CVSS v3 Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Published
2026-09-29
Last Modified
2026-09-29

Frequently asked questions

What is CVE-2026-102566?

CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.

Is CVE-2026-102566 actively exploited?

Active exploitation of CVE-2026-102566 has not been confirmed.

What is the CVSS score for CVE-2026-102566?

CVE-2026-102566 has a CVSS v3 base score of 7.8 (HIGH severity), with vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

Is CVE-2026-102566 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key