Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88050— Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values

Quick assessment

Affected
tesseract-ocr tesseract
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tesseract 是一个开源的光学字符识别(OCR)引擎。在 5.5.3 及更早版本中, 中的 函数虽然校验了 ,但会接受由精心构造的 重编码器(recoder)组件传入的负数 值。随后, 中的 函数可能因此产生等于零的 。接着, 会使用负数 在一个大小为 0 的向量上对 进行索引操作。由此导致的越界位写入使用了较大的回绕索引,并在默认 LSTM 引擎上可靠地引发野指针崩溃或内存分配失败。截至本次审查,尚未有修复版本发布。

CVSS 6.9 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88050

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values
Source: CVE Program / CVE List V5
Vulnerability Description
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component. UnicharCompress::ComputeCodeRange in src/ccutil/unicharcompress.cpp can consequently produce code_range_ equal to zero, after which SetupDecoder indexes is_valid_start_ with the negative code on a size-zero vector. The resulting out-of-bounds bit write uses a large wrapped index and reliably causes a wild-address crash or allocation failure on the default LSTM engine. No fixed release is available as of this review.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
tesseract-ocr tesseract <= 5.5.3 -

II. Public POCs for CVE-2026-88050

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88050

登录查看更多情报信息。

Patches & Fixes for CVE-2026-88050 (1)

Vendor Advisories for CVE-2026-88050 (1)

Same Patch Batch · tesseract-ocr · 2026-09-10 · 8 CVEs total

CVE-2026-88049 8.6 HIGH Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatc
CVE-2026-88048 8.6 HIGH Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matri
CVE-2026-88047 8.6 HIGH Tesseract: ReadNormProtos stack buffer overflow
CVE-2026-88051 8.6 HIGH Tesseract: Heap out-of-bounds write in GenericVector<T>::read due to independent reserved/
CVE-2026-88053 8.6 HIGH Tesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts i
CVE-2026-88052 7.8 HIGH Tesseract: Heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert desynch
CVE-2026-88054 6.9 MEDIUM Tesseract: Denial of service via empty-stack dereference in Plumbing/Series at model load

IV. Related Vulnerabilities

V. Comments for CVE-2026-88050

No comments yet


Leave a comment