Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-73066— Tesseract: Heap out-of-bounds write in LSTM Convolve layer via crafted .traineddata

Quick assessment

Affected
tesseract-ocr tesseract
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

tesseract-ocr tesseract是tesseract-ocr组织的一款光学字符识别引擎。 tesseract-ocr tesseract 5.5.3之前版本存在缓冲区错误漏洞,该漏洞源于反序列化器加载特制的.traineddata LSTM模型组件时,Convolve::DeSerialize中存在未检查的带符号整数乘法,导致卷积输出通道数回绕,使前向传递输出缓冲区大小不足,写入时使用未回绕的元素计数,从而造成堆越界写入。

CVSS 6.8 · Medium EPSS 0.13% · P3

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 1

VendorProduct Version RangeStatus
tesseract-ocr tesseract < 5.5.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73066

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tesseract: Heap out-of-bounds write in LSTM Convolve layer via crafted .traineddata
Source: CVE Program / CVE List V5
Vulnerability Description
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5
Vulnerability Title
tesseract-ocr tesseract 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
tesseract-ocr tesseract是tesseract-ocr组织的一款光学字符识别引擎。 tesseract-ocr tesseract 5.5.3之前版本存在缓冲区错误漏洞,该漏洞源于反序列化器加载特制的.traineddata LSTM模型组件时,Convolve::DeSerialize中存在未检查的带符号整数乘法,导致卷积输出通道数回绕,使前向传递输出缓冲区大小不足,写入时使用未回绕的元素计数,从而造成堆越界写入。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
tesseract-ocr tesseract < 5.5.3 -

II. Public POCs for CVE-2026-73066

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73066

登录查看更多情报信息。

Patches & Fixes for CVE-2026-73066 (3)

Vendor Advisories for CVE-2026-73066 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-73066

No comments yet


Leave a comment