VendorsGGMLllama.cppany version
Vulnerabilities

GGML Llama.cpp any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2024-42479
llama.cpp allows write-what-where in rpc_server::set_tensor
Published 2024-08-12 · Analyzed
10.0EPSS 0.026
CVE-2024-21802
A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-26 · Analyzed
9.8EPSS 0.014
CVE-2024-21825
A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-26 · Analyzed
9.8EPSS 0.013
CVE-2024-21836
A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-26 · Analyzed
9.8EPSS 0.013
CVE-2024-23496
A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-26 · Analyzed
9.8EPSS 0.013
CVE-2024-23605
A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-26 · Analyzed
9.8EPSS 0.013
CVE-2026-34159
llama.cpp: Unauthenticated RCE via GRAPH_COMPUTE buffer=0 bypass in llama.cpp RPC backend
Published 2026-04-01 · Analyzed
9.8EPSS 0.012
CVE-2024-42478
llama.cpp allows Arbitrary Address Read in rpc_server::get_tensor
Published 2024-08-12 · Analyzed
9.8EPSS 0.006
CVE-2026-21869
llama.cpp has Out-of-bounds Write in llama-server
Published 2026-01-07 · Analyzed
9.8EPSS 0.005
CVE-2026-43629
llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore
Published 2026-08-06 · Analyzed
9.2EPSS 0.007
CVE-2026-43631
llama.cpp b7492–b9060 Use-After-Free RCE via llama-server
Published 2026-08-06 · Analyzed
9.2EPSS 0.006
CVE-2026-43632
llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints
Published 2026-08-06 · Analyzed
9.2EPSS 0.005
CVE-2024-32878
Use of Uninitialized Variable Vulnerability in llama.cpp
Published 2024-04-26 · Analyzed
8.8EPSS 0.007
CVE-2025-49847
llama.cpp Vulnerable to Buffer Overflow via Malicious GGUF Model
Published 2025-06-17 · Analyzed
8.8EPSS 0.005
CVE-2025-52566
llama.cpp tokenizer signed vs. unsigned heap overflow
Published 2025-06-24 · Analyzed
8.8EPSS 0.003
CVE-2026-43628
llama.cpp b3978–b9058 Integer Underflow via DRY Sampler
Published 2026-08-06 · Analyzed
8.5EPSS 0.002
CVE-2026-70638
llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp
Published 2026-08-06 · Analyzed
8.5EPSS 0.002
CVE-2026-43622
llama.cpp b1886–b7445 Double Free via llama-android.cpp
Published 2026-08-06 · Analyzed
8.5EPSS 0.002
CVE-2026-43627
llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function
Published 2026-08-06 · Analyzed
8.5EPSS 0.002
CVE-2026-33298
llama.cpp has a Heap Buffer Overflow via Integer Overflow in GGUF Tensor Parsing
Published 2026-03-24 · Analyzed
7.8EPSS 0.004
CVE-2026-27940
llama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 Fix
Published 2026-03-12 · Analyzed
7.8EPSS 0.002
CVE-2026-52132
llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank.
Published 2026-09-01 · Analyzed
7.5EPSS 0.006
CVE-2026-52130
llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.
Published 2026-09-01 · Analyzed
7.5EPSS 0.005
CVE-2024-42477
llama.cpp global-buffer-overflow in ggml_type_size
Published 2024-08-12 · Analyzed
7.5EPSS 0.005
CVE-2026-52131
llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-70640
llama.cpp b1886–b7445 Race Condition Use-After-Free via llama-android.cpp
Published 2026-08-06 · Analyzed
7.3EPSS 0.002
CVE-2026-70639
llama.cpp b1886–b7445 Null Pointer Dereference DoS via llama-android.cpp
Published 2026-08-06 · Analyzed
6.8EPSS 0.002
CVE-2026-43630
llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure
Published 2026-08-06 · Analyzed
6.5EPSS 0.005
CVE-2024-41130
llama.cpp null pointer dereference in gguf_init_from_file
Published 2024-07-22 · Analyzed
6.5EPSS 0.003