CVE-2026-1260

Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.
Configurations

Configuration 1 (hide)

cpe:2.3:a:google:sentencepiece:*:*:*:*:*:*:*:*

History

30 Jun 2026, 03:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:3713 -
  • () https://access.redhat.com/errata/RHSA-2026:3782 -
  • () https://access.redhat.com/security/cve/CVE-2026-1260 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2432079 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1260.json -

17 Jun 2026, 10:15

Type Values Removed Values Added
Summary
  • (es) Acceso a memoria no válido en versiones de Sentencepiece inferiores a la 0.2.1 al usar un archivo de modelo vulnerable, que no se crea en el procedimiento de entrenamiento normal.

30 Jan 2026, 18:33

Type Values Removed Values Added
CPE cpe:2.3:a:google:sentencepiece:*:*:*:*:*:*:*:*
First Time Google sentencepiece
Google
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://github.com/google/sentencepiece/releases/tag/v0.2.1 - () https://github.com/google/sentencepiece/releases/tag/v0.2.1 - Product, Release Notes

22 Jan 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-22 17:16

Updated : 2026-07-15 02:18


NVD link : CVE-2026-1260

Mitre link : CVE-2026-1260

CVE.ORG link : CVE-2026-1260


JSON object : View

Products Affected

google

  • sentencepiece
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer