Description
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whitespace-delimited token into a fixed 61-byte stack buffer without setting a stream width. The 100-byte line buffer can carry a token of up to 99 characters, so a token longer than 60 characters writes up to 39 attacker-controlled bytes past the buffer during TessBaseAPI::Init of the legacy engine, causing stack corruption, denial of service, and potentially control-flow hijacking on affected standard-library implementations. Builds using Apple's libc++ C++20 bounded array overload are incidentally protected, while typical libstdc++ builds remain affected. No fixed release is available as of this review.
Published: 2026-09-10
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and potential Control‑Flow Hijacking
Action: Assess Impact
AI Analysis

Impact

Tesseract OCR’s ReadNormProtos parses a NORMPROTO token from a .traineddata file into a fixed 61‑byte stack buffer using operator>>(char*) without setting a stream width. Tokens longer than 60 characters result in a stack buffer overflow, allowing up to 39 bytes of attacker‑controlled memory to be written during TessBaseAPI::Init. The resulting corruption can cause the engine to crash or, on standard‑library implementations that do not enforce bounds, enable control‑flow hijacking. The flaw corresponds to buffer‑overflow weaknesses (CWE‑120, CWE‑121).

Affected Systems

All builds of Tesseract OCR 5.5.3 and earlier that use libstdc++ or other standard libraries lacking bounds enforcement are affected. Builds that employ Apple’s libc++ with C++20 bounded array overload are incidentally protected. The vulnerability is triggered when the engine loads an untrusted or malicious .traineddata file, so any installation that processes externally sourced traineddata is at risk.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog, so known exploitation prevalence is unknown. An attacker only needs to supply a crafted traineddata file that drives TessBaseAPI::Init; the stack overflow can lead to denial of service and, in vulnerable standard‑library builds, may allow control‑flow hijacking. Until a patched version or a reliable mitigation is deployed, the risk remains high.

Generated by OpenCVE AI on September 11, 2026 at 04:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Validate all .traineddata files against known checksums or a secure distribution before loading them into the OCR engine.
  • Rebuild Tesseract using a C++ standard library that enforces bounds, such as Apple’s libc++ with C++20 bounded array overload, or apply a local source patch that limits the input token length during parsing.
  • Restrict the OCR engine to load traineddata files only from a secured, authenticated directory and block all other paths.
  • Await and apply an official patch or fixed release from the Tesseract maintainers once it becomes available.

Generated by OpenCVE AI on September 11, 2026 at 04:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tesseract-ocr
Tesseract-ocr tesseract Ocr
CPEs cpe:2.3:a:tesseract-ocr:tesseract_ocr:*:*:*:*:*:*:*:*
Vendors & Products Tesseract-ocr
Tesseract-ocr tesseract Ocr
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sun, 13 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Tesseract Project
Tesseract Project tesseract
Vendors & Products Tesseract Project
Tesseract Project tesseract

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whitespace-delimited token into a fixed 61-byte stack buffer without setting a stream width. The 100-byte line buffer can carry a token of up to 99 characters, so a token longer than 60 characters writes up to 39 attacker-controlled bytes past the buffer during TessBaseAPI::Init of the legacy engine, causing stack corruption, denial of service, and potentially control-flow hijacking on affected standard-library implementations. Builds using Apple's libc++ C++20 bounded array overload are incidentally protected, while typical libstdc++ builds remain affected. No fixed release is available as of this review.
Title Tesseract: ReadNormProtos stack buffer overflow
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tesseract-ocr Tesseract Ocr
Tesseract Project Tesseract
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-11T20:33:10.471Z

Reserved: 2026-09-09T21:22:45.433Z

Link: CVE-2026-88047

cve-icon Vulnrichment

Updated: 2026-09-11T16:48:38.148Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T17:17:08.817

Modified: 2026-09-14T20:01:21.213

Link: CVE-2026-88047

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T16:18:01Z

Links: CVE-2026-88047 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:30:18Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-121

    Stack-based Buffer Overflow