Out-of-Bounds Read Vulnerability in EricLBuehler Mistral.rs GGUF Tokenizer
CVE-2026-75090

5.3MEDIUM

Key Information:

Vendor
CVE Published:
18 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-75090?

A vulnerability in the GGUF Tokenizer component of EricLBuehler Mistral.rs, specifically in the convert_gguf_to_hf_tokenizer function, exposes systems to out-of-bounds reads due to improper handling of parameters like eos_token_id, bos_token_id, and unknown_token_id. This issue, impacting versions up to 0.8.22, can be exploited remotely, thereby increasing the risk of potential attacks. It is highly recommended to upgrade to version 0.8.23, which contains a patch to resolve this security concern.

Affected Version(s)

Mistral.rs 0.8.0

Mistral.rs 0.8.1

Mistral.rs 0.8.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

m00dy (VulDB User)
.