CVE-2021-36081

Executive Summary

Tesseract OCR 5.0.0-alpha-20201231 contains a use‑after‑free vulnerability (CVE‑2021‑36081) triggered by a strpbrk call during one_ell_conflict handling. The flaw can lead to memory corruption, potentially allowing an attacker to execute arbitrary code or crash the OCR process. No current CISA KEV listing, but mitigations include updating to a patched release or disabling the vulnerable feature.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2021-07-01T03:15:08.620 - Last Modified: 2026-09-14T14:14:21.223

Original Description: Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.

"You get peace of mind not by thinking about it or imagining it, but by quietening and relaxing the restless mind."

— Remez Sasson
Source: NVD