{"id":"CVE-2026-1260","aliases":["GHSA-38vq-g6vr-w8wf","PYSEC-2026-1909"],"url":"https://o3.security/vulnerability/CVE-2026-1260","summary":"Invalid Memory Access in Sentencepiece,","details":"Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.","published":"2026-01-22T17:06:17.340Z","modified":"2026-08-05T03:32:26.567605171Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"sentencepiece","fixedVersion":"0.2.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/google/sentencepiece/releases/tag/v0.2.1"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1260.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3713"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3782"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-1260"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1260.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1260"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2432079"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-05T03:32:26.567605171Z"}}