Denial of Service Vulnerability in Tesseract OCR Engine by Tesseract Software
CVE-2026-88054
6.9MEDIUM
What is CVE-2026-88054?
The Tesseract OCR Engine suffers from a denial of service vulnerability due to improper handling of crafted .traineddata models. In versions 5.5.3 and earlier, a zero-length network stack for specific layer types can lead to a crash when initializing the LSTM recognizer. This occurs in the CacheXScaleFactor function, resulting in dereferencing an invalid pointer and causing a deterministic failure during model loading. Users of affected versions are advised to exercise caution and prepare for potential disruptions until a patched release is available.
Affected Version(s)
tesseract <= 5.5.3
