PulseAugur
EN
LIVE 03:54:04

CTranslate2 inference engine vulnerable to code execution and memory disclosure

Two critical vulnerabilities, CVE-2026-102566 and CVE-2026-102567, have been identified in CTranslate2, an inference engine used by Whisper and OpenNMT. These flaws, related to the model loader, can lead to arbitrary code execution or memory disclosure/crashes when a malicious model file is loaded. The vulnerabilities affect all versions prior to 4.8.1, and users are advised to update to the patched version. AI

IMPACT Critical vulnerabilities in CTranslate2 could expose AI models and systems to security risks, necessitating prompt patching.

RANK_REASON Identifies vulnerabilities in an AI inference engine, which is a software tool.

Read on Mastodon — mastodon.social →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

CTranslate2 inference engine vulnerable to code execution and memory disclosure

COVERAGE [1]

  1. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🚨 CTranslate2 CVE-2026-102566 & CVE-2026-102567 The inference engine behind Whisper & OpenNMT has two memory flaws in its model loader: CVE-2026-102566 (CVSS 7.

    🚨 CTranslate2 CVE-2026-102566 & CVE-2026-102567 The inference engine behind Whisper & OpenNMT has two memory flaws in its model loader: CVE-2026-102566 (CVSS 7.8) — heap buffer overflow → arbitrary code execution CVE-2026-102567 (CVSS 6.1) — OOB read → memory disclosure / crash A…