{"id":"CVE-2026-92786","summary":"LightGBM through 4.7.0 Out-of-Bounds Write via Crafted Model","details":"LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_ buffer during feature contribution computation.","modified":"2026-09-23T03:30:36.991861774Z","published":"2026-09-16T20:32:43.282Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92786.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92786.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92786"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/lightgbm-through-4.7.0-out-of-bounds-write-via-crafted-model"},{"type":"REPORT","url":"https://github.com/lightgbm-org/LightGBM/issues/7357"},{"type":"PACKAGE","url":"https://github.com/lightgbm-org/LightGBM"},{"type":"ARTICLE","url":"https://github.com/lightgbm-org/LightGBM/blob/v4.6.0/include/LightGBM/tree.h#L691-L698"},{"type":"ARTICLE","url":"https://github.com/lightgbm-org/LightGBM/blob/v4.6.0/src/io/tree.cpp#L750-L766"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lightgbm-org/lightgbm","events":[{"introduced":"0"},{"fixed":"8f7036f03627054d5a54a6f965b13f4b9ff2cb63"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"0"},{"last_affected":"4.7.0"},{"fixed":"4.7.0"}]}}],"versions":["v4.6.0","v4.5.0","v4.4.0","v4.3.0","v4.2.0","v4.1.0","v4.0.0","v3.2.1","v3.3.1","v3.3.0","v3.2.0","v3.1.1","v3.1.0","v3.0.0","v3.0.0rc1","v2.3.0","v2.2.3","v2.2.2","v2.2.1","v2.2.0","v2.1.2","v2.1.1","v2.1.0","v2.0.12","v2.0.11","v2.0.10","v2.0.8","v2.0.7","v2.0.4","v2.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92786.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}