PT-2026-76901 · Ericlbuehler · Mistral.Rs

·

CVE-2026-75090

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions EricLBuehler Mistral.rs versions prior to 0.8.23
Description A remote out-of-bounds read can occur within the GGUF Tokenizer component. The issue exists in the convert gguf to hf tokenizer() function located in the mistralrs-core/src/gguf/gguf tokenizer.rs file. This occurs when the eos token id, bos token id, or unknown token id arguments are manipulated.
Recommendations Update to version 0.8.23.

Exploit

Fix

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75090

Affected Products

Mistral.Rs