Executive brief
A vulnerability exists in whisper.cpp, a high-performance C++ implementation of OpenAI's Whisper speech recognition model. When the software processes an extremely short audio file (fewer than 201 samples), it may read memory outside of the intended buffer. This could allow a local attacker to access small amounts of potentially sensitive information from the application's memory, though it does not allow for system takeover or data modification.
Technical details
An out-of-bounds read vulnerability exists in whisper.cpp version 1.8.4-58 within the log_mel_spectrogram function in src/whisper.cpp. The issue stems from the use of std::reverse_copy to apply reflective padding to the start of an audio signal. The function attempts to copy a fixed number of samples (stage_2_pad, typically 200) regardless of the actual input length. If a user provides an audio buffer with fewer than 201 samples, the source range for the copy operation extends beyond the allocated heap buffer. This can be triggered via any API path that accepts user-supplied audio, such as whisper_full(). A pull request (#3925) has been submitted to reject inputs that are too short for the required padding.
Affected products
- ggml-org whisper.cpp 1.8.4-58
Timeline
- 2026-07-03: disclosed: Issue reported on GitHub repository
- 2026-07-04: other: Pull request submitted to fix the issue
- 2026-07-27: advisory: CVE published and NVD record created