{"id":"OSV-2026-646","summary":"Heap-buffer-overflow in sentencepiece::unigram::Model::EncodeOptimized","details":"OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=507169860\n\n```\nCrash type: Heap-buffer-overflow READ 8\nCrash state:\nsentencepiece::unigram::Model::EncodeOptimized\nsentencepiece::unigram::Model::Encode\nsentencepiece::SentencePieceProcessor::Encode\n```\n","modified":"2026-05-03T12:15:15.048268Z","published":"2026-04-29T00:04:02.164830Z","references":[{"type":"REPORT","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=507169860"}],"affected":[{"package":{"name":"sentencepiece","ecosystem":"OSS-Fuzz","purl":"pkg:generic/sentencepiece"},"ranges":[{"type":"GIT","repo":"https://github.com/google/sentencepiece.git","events":[{"introduced":"ea83729ca83c4696a775d3d1e8a03e3bd4fa8d97"},{"fixed":"eb3ba49278fd10e5ae7b1d71c87f50e5a842f541"}]}],"ecosystem_specific":{"severity":"MEDIUM"},"database_specific":{"source":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/sentencepiece/OSV-2026-646.yaml","fixed_range":"c1f97156bbd3b3ac8346f0b738b87f4e60fb857c:eb3ba49278fd10e5ae7b1d71c87f50e5a842f541"}}],"schema_version":"1.7.5"}