CVE-2026-107183
- EPSS 0.42%
- Veröffentlicht 07.10.2026 13:35:41
- Zuletzt bearbeitet 07.10.2026 15:57:20
llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser...
CVE-2026-52132
- EPSS 0.33%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 04.09.2026 20:15:30
llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank.
CVE-2026-52131
- EPSS 0.26%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 04.09.2026 20:20:23
llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.
CVE-2026-52130
- EPSS 0.28%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 04.09.2026 20:21:58
llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.
CVE-2026-78148
- EPSS 0.54%
- Veröffentlicht 24.08.2026 00:16:46
- Zuletzt bearbeitet 24.08.2026 18:17:24
A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Executing a manipulation can lead to null pointer derefer...
CVE-2026-78147
- EPSS 0.43%
- Veröffentlicht 23.08.2026 23:16:46
- Zuletzt bearbeitet 27.08.2026 17:20:33
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params res...
CVE-2026-39909
- EPSS 0.77%
- Veröffentlicht 21.08.2026 17:16:30
- Zuletzt bearbeitet 03.09.2026 13:05:37
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-70640
- EPSS 0.16%
- Veröffentlicht 06.08.2026 22:18:28
- Zuletzt bearbeitet 21.09.2026 18:10:49
llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while Thread B con...
CVE-2026-70638
- EPSS 0.13%
- Veröffentlicht 06.08.2026 22:18:28
- Zuletzt bearbeitet 21.09.2026 18:11:01
llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation,...
CVE-2026-70639
- EPSS 0.13%
- Veröffentlicht 06.08.2026 22:18:28
- Zuletzt bearbeitet 21.09.2026 18:10:56
llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing it. Attackers can supply a malic...