Description
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left NetworkIO::WriteTimeStepPart and NetworkIO::AddTimeStepPart unchecked. In LSTM::Forward in src/lstm/lstm.cpp, source_ is sized from the independently deserialized na_ field while the WriteTimeStepPart count is ns_, which comes from the CI gate WeightMatrix dim1() value. A crafted NT_LSTM layer can make ns_ much larger than na_, causing a heap out-of-bounds write during the first recognition step on the default LSTM engine and resulting in heap corruption, a crash, or potentially controlled corruption. No fixed release is available as of this review.
Published: 2026-09-10
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Heap memory corruption
Action: Monitor
AI Analysis

Impact

A crafted NT_LSTM layer that sets the gate-matrix dimension greater than the deserialized na_ field in Tesseract’s default LSTM engine causes a heap out-of-bounds write during the first recognition step. The resulting heap corruption can lead to a crash or, if the attacker controls the model data, potentially controlled alteration of nearby memory. This flaw resides in the low-level LSTM implementation and is triggered by an improperly validated model input. The weakness is a type of out-of-bounds buffer overwrite (CWE-787).

Affected Systems

The vulnerability impacts the Tesseract OCR engine provided by tesseract-ocr for versions 5.5.3 and earlier. Any system that processes custom .traineddata files or LSTM models containing the vulnerable NT_LSTM layer is affected, regardless of whether the input originates internally or externally.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. Because the flaw is locally exploitable, an attacker must supply a specially crafted LSTM model file; no public exploits are documented and the EPSS score is unavailable. The likely attack vector is the injection of a malicious traineddata file into the OCR pipeline; this is inferred from the description. The vulnerability is not listed in CISA’s KEV catalog, suggesting that there is currently no widespread automated exploitation. However, systems that accept untrusted model data should still treat the vulnerability as a serious risk potential code execution if the attacker can influence the corrupted memory region.

Generated by OpenCVE AI on September 11, 2026 at 00:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Accept only signed or otherwise cryptographically verified traineddata and LSTM model files; reject any untrusted or unsigned models.
  • Disable the default LSTM engine for any processing that may involve untrusted model files, or replace it with a non-vulnerable OCR implementation if possible.
  • Deploy runtime stack canaries, and control-flow guard to reduce the effectiveness of an exploit that succeeds in corrupting heap memory.

Generated by OpenCVE AI on September 11, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tesseract-ocr
Tesseract-ocr tesseract Ocr
CPEs cpe:2.3:a:tesseract-ocr:tesseract_ocr:*:*:*:*:*:*:*:*
Vendors & Products Tesseract-ocr
Tesseract-ocr tesseract Ocr
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Sun, 13 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Tesseract Project
Tesseract Project tesseract
Vendors & Products Tesseract Project
Tesseract Project tesseract

Fri, 11 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left NetworkIO::WriteTimeStepPart and NetworkIO::AddTimeStepPart unchecked. In LSTM::Forward in src/lstm/lstm.cpp, source_ is sized from the independently deserialized na_ field while the WriteTimeStepPart count is ns_, which comes from the CI gate WeightMatrix dim1() value. A crafted NT_LSTM layer can make ns_ much larger than na_, causing a heap out-of-bounds write during the first recognition step on the default LSTM engine and resulting in heap corruption, a crash, or potentially controlled corruption. No fixed release is available as of this review.
Title Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatch
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tesseract-ocr Tesseract Ocr
Tesseract Project Tesseract
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-10T17:13:02.365Z

Reserved: 2026-09-09T21:22:45.433Z

Link: CVE-2026-88049

cve-icon Vulnrichment

Updated: 2026-09-10T17:12:54.829Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T17:17:09.087

Modified: 2026-09-14T20:01:48.403

Link: CVE-2026-88049

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T16:23:18Z

Links: CVE-2026-88049 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:30:18Z

Weaknesses