MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 7 h ago, last 7 h ago, peak #2

Two memory flaws found in CTranslate2 inference engine

Original: 🚨 CTranslate2 CVE-2026-102566 & CVE-2026-102567 The inference engine behind Whisper & OpenNMT has two memory flaws in it

Security researchers have disclosed two vulnerabilities in CTranslate2, the machine learning inference engine used by Whisper and OpenNMT. CVE-2026-102566, rated CVSS 7.8, is a heap buffer overflow in the model loader that could allow arbitrary code execution, while CVE-2026-102567, rated 6.1, is an out-of-bounds read enabling memory disclosure or crashes. Developers running speech recognition or translation services are being urged to patch.

Why now: CTranslate2 is widely deployed in AI speech and translation systems, so memory flaws that could enable code execution raise immediate security concerns.

CTranslate2WhisperOpenNMTCVE-2026-102566CVE-2026-102567

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/427850