Out-of-bounds read in tesseract - #VU140985
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the DAWG dictionary loader when parsing a crafted .traineddata model file during initialization. A remote attacker can supply a specially crafted .traineddata model file to cause a denial of service.
The issue is triggered at model-load time before any image is processed.