Mmastodon TechnologyCybersecurity first seen 3 h ago, last 3 h ago, peak #2
Two memory flaws found in CTranslate2 inference engine
Original: 🚨 CTranslate2 CVE-2026-102566 & CVE-2026-102567 The inference engine behind Whisper & OpenNMT has two memory flaws in it
Security researchers have disclosed two vulnerabilities in CTranslate2, the machine learning inference engine used by Whisper and OpenNMT. CVE-2026-102566, rated CVSS 7.8, is a heap buffer overflow in the model loader that could allow arbitrary code execution, while CVE-2026-102567, rated 6.1, is an out-of-bounds read enabling memory disclosure or crashes. Developers running speech recognition or translation services are being urged to patch.
Why now: CTranslate2 is widely deployed in AI speech and translation systems, so memory flaws that could enable code execution raise immediate security concerns.
CTranslate2WhisperOpenNMTCVE-2026-102566CVE-2026-102567
Rank over time, top of the chart is #1. 2 snapshots from 3 h ago to 3 h ago.
Evidence
- 🚨 CTranslate2 CVE-2026-102566 & CVE-2026-102567 The inference engine behind Whisper & OpenNMT has two memory flaws in its model loader: CVE-2026-102566 (CVSS 7.8) — heap buffer overflow → arbitrary code execution CVE-2026-102567 (CVSS 6.1) — OOB read → memory disclosure / crash… · threataft@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/427850