—
PYSEC-2026-1909
Sentencepiece has a a heap overflow issue
Quick fix
PYSEC-2026-1909 — sentencepiece: upgrade to the fixed version with the command below.
pip install --upgrade 'sentencepiece>=0.2.1'Details
Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-1260[ADVISORY]
- https://github.com/google/sentencepiece/commit/d856b67fdb3492e035489abf9b3aaf486144b2c0[WEB]
- https://github.com/google/sentencepiece[PACKAGE]
- https://github.com/google/sentencepiece/releases/tag/v0.2.1[WEB]
- https://pypi.org/project/sentencepiece[PACKAGE]
- https://github.com/advisories/GHSA-38vq-g6vr-w8wf[ADVISORY]