Two critical vulnerabilities, CVE-2026-102566 and CVE-2026-102567, have been identified in CTranslate2, an inference engine used by Whisper and OpenNMT. These flaws, related to the model loader, can lead to arbitrary code execution or memory disclosure/crashes when a malicious model file is loaded. The vulnerabilities affect all versions prior to 4.8.1, and users are advised to update to the patched version. AI
IMPACT Critical vulnerabilities in CTranslate2 could expose AI models and systems to security risks, necessitating prompt patching.
RANK_REASON Identifies vulnerabilities in an AI inference engine, which is a software tool.
Read on Mastodon — mastodon.social →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →