Out-of-Bounds Read Vulnerability in EricLBuehler Mistral.rs GGUF Tokenizer
CVE-2026-75090
Key Information:
- Vendor
Ericlbuehler
- Status
- Vendor
- CVE Published:
- 18 August 2026
Badges
What is CVE-2026-75090?
A vulnerability in the GGUF Tokenizer component of EricLBuehler Mistral.rs, specifically in the convert_gguf_to_hf_tokenizer function, exposes systems to out-of-bounds reads due to improper handling of parameters like eos_token_id, bos_token_id, and unknown_token_id. This issue, impacting versions up to 0.8.22, can be exploited remotely, thereby increasing the risk of potential attacks. It is highly recommended to upgrade to version 0.8.23, which contains a patch to resolve this security concern.
Affected Version(s)
Mistral.rs 0.8.0
Mistral.rs 0.8.1
Mistral.rs 0.8.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
