Ggml
Ggml Llama.cpp: vulnerabilidades y CVE
Ggml Llama.cpp tiene 37 vulnerabilidades publicadas, 24 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE37
Últimos 12 meses24
Críticas12
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86317 | Media (6.9) | 0.70% | — | 7 sept 2026 | A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component RPC Server. Performing a manipulation… |
| CVE-2026-52132 | Alta (7.5) | 0.59% | — | 1 sept 2026 | llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank. |
| CVE-2026-52131 | Alta (7.5) | 0.43% | — | 1 sept 2026 | llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function. |
| CVE-2026-52130 | Alta (7.5) | 0.49% | — | 1 sept 2026 | llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service. |
| CVE-2026-78148 | Media (6.9) | 0.72% | — | 24 ago 2026 | A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Executing a manipulation… |
| CVE-2026-78147 | Media (6.9) | 0.56% | — | 23 ago 2026 | A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation… |
| CVE-2026-70640 | Alta (7.3) | 0.24% | — | 6 ago 2026 | llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on… |
| CVE-2026-70639 | Media (6.8) | 0.19% | — | 6 ago 2026 | llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing… |
| CVE-2026-70638 | Alta (8.5) | 0.23% | — | 6 ago 2026 | llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max… |
| CVE-2026-43632 | Crítica (9.2) | 0.48% | — | 6 ago 2026 | llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and… |
| CVE-2026-43631 | Crítica (9.2) | 0.57% | — | 6 ago 2026 | llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to… |
| CVE-2026-43630 | Media (6.3) | 0.50% | — | 6 ago 2026 | llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore path that allows attackers with write access to the slot save directory to read memory past the end… |
| CVE-2026-43629 | Crítica (9.2) | 0.70% | — | 6 ago 2026 | llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers… |
| CVE-2026-43628 | Alta (8.5) | 0.23% | — | 6 ago 2026 | llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted… |
| CVE-2026-43627 | Alta (8.5) | 0.20% | — | 6 ago 2026 | llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation… |
| CVE-2026-43622 | Alta (8.5) | 0.23% | — | 6 ago 2026 | llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete… |
| CVE-2026-18581 | Baja (1.9) | 0.16% | — | 3 ago 2026 | A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. Executing a… |
| CVE-2026-17501 | Media (6.9) | 0.72% | — | 27 jul 2026 | A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation… |
| CVE-2026-17500 | Media (6.9) | 0.72% | — | 27 jul 2026 | A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The… |
| CVE-2026-34159 | Crítica (9.8) | 1.2% | — | 1 abr 2026 | llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthenticated attacker can… |
| CVE-2026-33298 | Alta (7.8) | 0.37% | — | 24 mar 2026 | llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting a GGUF file with… |
| CVE-2026-27940 | Alta (7.8) | 0.18% | — | 12 mar 2026 | llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Using the subsequent… |
| CVE-2026-2069 | Baja (1.9) | 0.13% | — | 6 feb 2026 | A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the file llama.cpp/src/llama-grammar.cpp of the component GBNF Grammar Handler. This manipulation causes… |
| CVE-2026-21869 | Crítica (9.8) | 0.52% | — | 8 ene 2026 | llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_discard parameter is parsed directly from JSON input in the llama.cpp server's completion endpoints without validation to… |
| CVE-2025-53630 | Alta (8.9) | 0.34% | — | 10 jul 2025 | llama.cpp is an inference of several LLM models in C/C++. Integer Overflow in the gguf_init_from_file_impl function in ggml/src/gguf.cpp can lead to Heap Out-of-Bounds Read/Write. This vulnerability is fixed in commit… |
| CVE-2025-52566 | Alta (8.8) | 0.36% | — | 24 jun 2025 | llama.cpp is an inference of several LLM models in C/C++. Prior to version b5721, there is a signed vs. unsigned integer overflow in llama.cpp's tokenizer implementation (llama_vocab::tokenize)… |
| CVE-2025-49847 | Alta (8.8) | 0.52% | — | 17 jun 2025 | llama.cpp is an inference of several LLM models in C/C++. Prior to version b5662, an attacker‐supplied GGUF model vocabulary can trigger a buffer overflow in llama.cpp’s vocabulary‐loading code. Specifically, the helper… |
| CVE-2024-42479 | Crítica (9.8) | 2.6% | — | 12 ago 2024 | llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address writing. This vulnerability is fixed in b3561. |
| CVE-2024-42478 | Crítica (9.8) | 0.60% | — | 12 ago 2024 | llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address reading. This vulnerability is fixed in b3561. |
| CVE-2024-42477 | Alta (7.5) | 0.46% | — | 12 ago 2024 | llama.cpp provides LLM inference in C/C++. The unsafe `type` member in the `rpc_tensor` structure can cause `global-buffer-overflow`. This vulnerability may lead to memory data leakage. The vulnerability is fixed in… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.