Executive brief
Sentencepiece, a widely used text processing library for machine learning models, contains a security vulnerability that can be triggered by loading a specially crafted, malicious model file. If an application or user processes such a file, it could lead to a complete system compromise, unauthorized data access, or service crashes. This issue primarily affects environments where users might download and use untrusted machine learning models from external sources.
Technical details
A heap buffer overflow vulnerability exists in Google Sentencepiece before version 0.2.1. The flaw is triggered during the loading of a vulnerable model file that contains an invalid precompiled normalization model, which is not typically generated during standard training procedures. An attacker can exploit this by providing a malicious model file to an application using the library. Successful exploitation requires the victim to load the crafted file (User Interaction) and can result in arbitrary code execution or a denial-of-service (DoS) condition. The issue has been addressed in Sentencepiece version 0.2.1, and Red Hat has released updated images for OpenShift AI to mitigate the risk.
Affected products
- Google Sentencepiece < 0.2.1
- Red Hat Red Hat OpenShift AI 2.25, 3.3
- Red Hat Red Hat AI Inference Server 3
Timeline
- 2026-01-22: disclosed
- 2026-01-22: advisory
- 2026-03-04: patched: Red Hat released security advisories RHSA-2026:3713 and RHSA-2026:3782
References
- https://github.com/google/sentencepiece/releases/tag/v0.2.1
- https://access.redhat.com/errata/RHSA-2026:3713
- https://access.redhat.com/errata/RHSA-2026:3782
- https://access.redhat.com/security/cve/CVE-2026-1260
- https://bugzilla.redhat.com/show_bug.cgi?id=2432079
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1260.json