Heap Out-of-Bounds Read in Tesseract OCR Engine
CVE-2026-73067
6.7MEDIUM
What is CVE-2026-73067?
A vulnerability exists in the Tesseract OCR engine, where a maliciously crafted .traineddata model can lead to unexpected behavior during initialization. Specifically, this issue occurs in the SquishedDawg::read_squished_dawg method, which may accept an unterminated forward-edge run. Consequently, this results in a heap out-of-bounds read and can cause the process to crash before any image processing occurs. This vulnerability has been addressed in Tesseract version 5.5.3.
Affected Version(s)
tesseract < 5.5.3
