Heap Out-of-Bounds Read in Tesseract OCR Engine
CVE-2026-73067

6.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73067?

A vulnerability exists in the Tesseract OCR engine, where a maliciously crafted .traineddata model can lead to unexpected behavior during initialization. Specifically, this issue occurs in the SquishedDawg::read_squished_dawg method, which may accept an unterminated forward-edge run. Consequently, this results in a heap out-of-bounds read and can cause the process to crash before any image processing occurs. This vulnerability has been addressed in Tesseract version 5.5.3.

Affected Version(s)

tesseract < 5.5.3

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.