{"data":{"id":"7f724a05-0e26-4f0d-b1be-1ce610f213bb","title":"GHSA-56r5-2p2f-7cxp: PocketSphinx: Buffer overflows in language and acoustic model loading code","summary":"PocketSphinx (a speech recognition library) versions up to 5prealpha have buffer overflow vulnerabilities (memory safety bugs where data overflows allocated memory boundaries) in code that reads language and acoustic model files. An attacker could exploit this by placing a malicious file in a directory specified by the POCKETSPHINX_PATH environment variable, especially if that directory is writable by untrusted users.","solution":"Update to PocketSphinx 5.1.1, which corrects the vulnerability. If updating is not immediately possible, ensure the POCKETSPHINX_PATH environment variable is either unset or points to a directory whose contents are trusted and cannot be written by untrusted users.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-56r5-2p2f-7cxp","publishedAt":"2026-07-17T21:19:17.000Z","cveId":"CVE-2026-54559","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["pocketsphinx@< 5.1.1 (fixed: 5.1.1)"],"affectedVendors":[],"affectedVendorsRaw":["PocketSphinx"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-07-17T21:19:17.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}