Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▲ 8 respecto a la semana anterior
Críticas / altas1461▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.70% | — | Ggml Llama.cppAI | 7/9/2026 | 8/9/2026 | A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component RPC Server. Performing a manipulation of the argument ne results in reachable assertion. The attack is possible to be carried out… | |
| Analizada | Alta (7.5) | 0.59% | — | Ggml Llama.cpp | 1/9/2026 | 4/9/2026 | llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank. | |
| Analizada | Alta (7.5) | 0.43% | — | Ggml Llama.cpp | 1/9/2026 | 4/9/2026 | llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function. | |
| Analizada | Alta (7.5) | 0.49% | — | Ggml Llama.cpp | 1/9/2026 | 4/9/2026 | llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service. | |
| Aplazada | Media (6.9) | 0.72% | — | Ggml Llama.cppAI | 24/8/2026 | 24/8/2026 | A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The pull request to fix… | |
| Aplazada | Media (6.9) | 0.56% | — | Ggml Llama.cppAI | 23/8/2026 | 27/8/2026 | A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params results in deserialization. The attack may be initiated remotely. This… | |
| Analizada | Alta (7.3) | 0.24% | — | Ggml Llama.cpp | 6/8/2026 | 21/9/2026 | llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while Thread B concurrently frees the llama_context. Attackers can exploit this by… | |
| Analizada | Media (6.8) | 0.19% | — | Ggml Llama.cpp | 6/8/2026 | 21/9/2026 | llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing it. Attackers can supply a malicious, corrupt, or truncated model file to trigger a null context… | |
| Analizada | Alta (8.5) | 0.23% | — | Ggml Llama.cpp | 6/8/2026 | 21/9/2026 | llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocation to wrap and allocate insufficient… | |
| Analizada | Crítica (9.2) | 0.48% | — | Ggml Llama.cpp | 6/8/2026 | 21/9/2026 | llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task queue and access ctx_server.vocab directly on HTTP worker threads.… | |
| Analizada | Crítica (9.2) | 0.57% | — | Ggml Llama.cpp | 6/8/2026 | 21/9/2026 | llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the vulnerability by sending requests to affected… | |
| Analizada | Media (6.3) | 0.50% | — | Ggml Llama.cpp | 6/8/2026 | 21/9/2026 | llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore path that allows attackers with write access to the slot save directory to read memory past the end of the allocated cells array. Attackers can craft a malicious slot file with an oversized seq_id… | |
| Analizada | Crítica (9.2) | 0.70% | — | Ggml Llama.cpp | 6/8/2026 | 21/9/2026 | llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corrupt heap memory. Attackers can craft… | |
| Analizada | Alta (8.5) | 0.23% | — | Ggml Llama.cpp | 6/8/2026 | 21/9/2026 | llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry_allowed_length set to INT32_MIN to the /v1/completions or /v1/chat/completions… | |
| Analizada | Alta (8.5) | 0.20% | — | Ggml Llama.cpp | 6/8/2026 | 21/9/2026 | llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap… | |
| Analizada | Alta (8.5) | 0.23% | — | Ggml Llama.cpp | 6/8/2026 | 4/9/2026 | llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata corruption. Attackers can trigger this memory management mismatch to cause… | |
| Aplazada | Baja (1.9) | 0.16% | — | Ggml Llama.cppAI | 3/8/2026 | 12/8/2026 | A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. Executing a manipulation with the input {{9|9|{ can lead to reachable assertion. The attack requires local access. The… | |
| Aplazada | Media (6.9) | 0.72% | — | Ggml Llama.cppAI | 27/7/2026 | 29/7/2026 | A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes uncontrolled recursion. The attack may be initiated remotely. The pull request to fix this issue… | |
| Aplazada | Media (6.9) | 0.72% | — | Ggml Llama.cppAI | 27/7/2026 | 27/7/2026 | A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched remotely. The pull request to fix this issue awaits acceptance. | |
| Analizada | Crítica (9.8) | 1.2% | — | Ggml Llama.cpp | 1/4/2026 | 17/6/2026 | llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthenticated attacker can read and write arbitrary process memory via crafted GRAPH_COMPUTE messages. Combined with pointer leaks… | |
| Analizada | Alta (7.8) | 0.37% | — | Ggml Llama.cpp | 24/3/2026 | 17/6/2026 | llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting a GGUF file with specific tensor dimensions. This causes `ggml_nbytes` to return a significantly smaller size than… | |
| Analizada | Alta (7.8) | 0.18% | — | Ggml Llama.cpp | 12/3/2026 | 17/6/2026 | llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Using the subsequent fread() writes 528+ bytes of attacker-controlled data past the buffer boundary. This is a bypass of a… | |
| Aplazada | Baja (1.9) | 0.13% | — | Ggml Llama.cppAI | 6/2/2026 | 17/6/2026 | A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the file llama.cpp/src/llama-grammar.cpp of the component GBNF Grammar Handler. This manipulation causes stack-based buffer overflow. The attack needs to be launched locally. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.52% | — | Ggml Llama.cpp | 8/1/2026 | 17/6/2026 | llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_discard parameter is parsed directly from JSON input in the llama.cpp server's completion endpoints without validation to ensure it's non-negative. When a negative value is supplied and the context fills up,… | |
| Aplazada | Alta (8.9) | 0.34% | — | Ggml Llama.cppAI | 10/7/2025 | 17/6/2026 | llama.cpp is an inference of several LLM models in C/C++. Integer Overflow in the gguf_init_from_file_impl function in ggml/src/gguf.cpp can lead to Heap Out-of-Bounds Read/Write. This vulnerability is fixed in commit 26a48ad699d50b6268900062661bd22f3e792579. |