SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-88049

MEDIUM · CVSS 5.5 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability affects Tesseract's LSTM engine, specifically in versions 5.5.3 and earlier, where unchecked bounds in certain functions can lead to heap out-of-bounds writes. This can result in heap corruption, application crashes, or potentially allow an attacker to manipulate memory, posing a significant risk to system stability and security. Organizations using Tesseract for OCR tasks should prioritize addressing this vulnerability, especially those operating in sensitive environments where data integrity is critical.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88049
Severity
MEDIUM
CVSS
5.5
EPSS
0.19%

Original NVD Description

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left NetworkIO::WriteTimeStepPart and NetworkIO::AddTimeStepPart unchecked. In LSTM::Forward in src/lstm/lstm.cpp, source_ is sized from the independently deserialized na_ field while the WriteTimeStepPart count is ns_, which comes from the CI gate WeightMatrix dim1() value. A crafted NT_LSTM layer can make ns_ much larger than na_, causing a heap out-of-bounds write during the first recognition step on the default LSTM engine and resulting in heap corruption, a crash, or potentially controlled corruption. No fixed release is available as of this review.

Related CVEs

Other vulnerabilities affecting the same vendor(s)