๐Ÿ” CVE Alert

CVE-2026-73066

UNKNOWN 0.0

Tesseract: Heap out-of-bounds write in LSTM Convolve layer via crafted .traineddata

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.

CWE CWE-787
Vendor tesseract-ocr
Product tesseract
Published Aug 11, 2026
Last Updated Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for tesseract-ocr tesseract

Be the first to know when new unknown vulnerabilities affecting tesseract-ocr tesseract are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

tesseract-ocr / tesseract
< 5.5.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-7j76-5rq5-5jg8 github.com: https://github.com/tesseract-ocr/tesseract/pull/4588 github.com: https://github.com/tesseract-ocr/tesseract/commit/2f4d2f4bf45c363785d7bf1da29b6628f8939a72 github.com: https://github.com/tesseract-ocr/tesseract/releases/tag/5.5.3