It was discovered that Tesseract incorrectly handled crafted .traineddata models. An attacker could possibly use this issue to cause Tesseract to crash, resulting in a denial of service. (CVE-2026-73067) It was discovered that Tesseract did not properly validate dimensions in crafted .traineddata models. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-73066) It was discovered that Tesseract did not properly limit token lengths in crafted .traineddata models. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-88047) It was discovered that Tesseract did not properly validate layer dimensions in crafted .traineddata models. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-88048) It was discovered that Tesseract did not properly validate layer sizes in crafted .traineddata models. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-88049) It was discovered that Tesseract incorrectly handled negative character codes in crafted .traineddata models. An attacker could possibly use this issue to cause Tesseract to crash, resulting in a denial of service. (CVE-2026-88050) It was discovered that Tesseract did not properly validate vector sizes in crafted .traineddata models. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-88051) It was discovered that Tesseract did not properly validate character IDs in crafted .traineddata models. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-88052) It was discovered that Tesseract did not properly validate classifier counts in crafted .traineddata models. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-88053) It was discovered that Tesseract incorrectly handled empty network layers in crafted .traineddata models. An attacker could possibly use this issue to cause Tesseract to crash, resulting in a denial of service. (CVE-2026-88054)