Heap Corruption Vulnerability in Tesseract OCR Engine by Google
CVE-2026-88053

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88053?

The Tesseract OCR engine suffers from a vulnerability where improperly validated loop bounds from a crafted .traineddata file can lead to heap out-of-bounds pointer writes. This occurs in versions 5.5.3 and earlier, during the initialization of legacy classifiers. The failure to validate values read from the TESSDATA_INTTEMP component allows for potential heap corruption, crashes, or even controlled corruption, significantly compromising system integrity.

Affected Version(s)

tesseract <= 5.5.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.