Description
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component. UnicharCompress::ComputeCodeRange in src/ccutil/unicharcompress.cpp can consequently produce code_range_ equal to zero, after which SetupDecoder indexes is_valid_start_ with the negative code on a size-zero vector. The resulting out-of-bounds bit write uses a large wrapped index and reliably causes a wild-address crash or allocation failure on the default LSTM engine. No fixed release is available as of this review.
Published: 2026-09-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds write causing crashes and potential denial of service
Action: Monitor
AI Analysis

Impact

T versions 5.5.3 and earlier allows negative code values to bypass length validation. This defect leads to an out‑of‑bounds bit write during decoding, causing wild‑address crashes or allocation failures in the default LSTM engine. The vulnerability is a classic buffer overflow (CWE‑787) and is rated as moderate severity with a CVSS score of 6.9.

Affected Systems

The flaw affects the Tesseract OCR engine, identified by the CNA as tesseract‑ocr:tesseract. All releases up to and including 5.5.3 are susceptible; no fixed release has been released at the time of review.

Risk and Exploitability

An attacker must supply a crafted .traineddata file containing a recoder with negative code values to trigger the defect. The attack vector is local or remote via untrusted OCR data. Because the flaw manifests during data loading, any system that processes external OCR input could be impacted. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate risk that is not currently widely exploited.

Generated by OpenCVE AI on September 11, 2026 at 00:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an official Tesseract upgrade when a patch version becomes available
  • Validate or filter recoder components in .traineddata files before loading them, ensuring that code values are non‑negative and within bounds
  • Run OCR processing in a sandboxed or isolated environment to contain any memory‑corruption crash from affecting the broader system

Generated by OpenCVE AI on September 11, 2026 at 00:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tesseract-ocr
Tesseract-ocr tesseract Ocr
CPEs cpe:2.3:a:tesseract-ocr:tesseract_ocr:*:*:*:*:*:*:*:*
Vendors & Products Tesseract-ocr
Tesseract-ocr tesseract Ocr
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Sun, 13 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Tesseract Project
Tesseract Project tesseract
Vendors & Products Tesseract Project
Tesseract Project tesseract

Fri, 11 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component. UnicharCompress::ComputeCodeRange in src/ccutil/unicharcompress.cpp can consequently produce code_range_ equal to zero, after which SetupDecoder indexes is_valid_start_ with the negative code on a size-zero vector. The resulting out-of-bounds bit write uses a large wrapped index and reliably causes a wild-address crash or allocation failure on the default LSTM engine. No fixed release is available as of this review.
Title Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tesseract-ocr Tesseract Ocr
Tesseract Project Tesseract
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-10T17:30:29.252Z

Reserved: 2026-09-09T21:22:45.433Z

Link: CVE-2026-88050

cve-icon Vulnrichment

Updated: 2026-09-10T17:28:26.035Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T17:17:09.223

Modified: 2026-09-14T20:02:01.503

Link: CVE-2026-88050

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T16:24:21Z

Links: CVE-2026-88050 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:30:18Z

Weaknesses