CVEs we hold for Ggml-org
Records whose assigning authority named Ggml-org as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-86317ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertionggml-org llama.cpp
CVE-2026-78148ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp graph_compute null pointer dereferenceggml-org llama.cpp
CVE-2026-78147ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp deserialize_tensor deserializationggml-org llama.cpp
CVE-2026-70640llama.cpp b1886–b7445 Race Condition Use-After-Free via llama-android.cppggml-org llama.cpp
CVE-2026-70639llama.cpp b1886–b7445 Null Pointer Dereference DoS via llama-android.cppggml-org llama.cpp
CVE-2026-70638llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cppggml-org llama.cpp
CVE-2026-43627llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Functionggml-org llama.cpp
CVE-2026-34159llama.cpp: Unauthenticated RCE via GRAPH_COMPUTE buffer=0 bypass in llama.cpp RPC backendggml-org llama.cpp
CVE-2026-33298llama.cpp has a Heap Buffer Overflow via Integer Overflow in GGUF Tensor Parsingggml-org llama.cpp
CVE-2026-27940llama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 Fixggml-org llama.cpp
CVE-2026-2069ggml-org llama.cpp GBNF Grammar llama-grammar.cpp llama_grammar_advance_stack stack-based overflowggml-org llama.cpp
CVE-2026-17501ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform recursionggml-org llama.cpp
CVE-2026-17500ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereferenceggml-org llama.cpp
CVE-2026-10298ggml-org whisper.cpp ggml.c whisper_model_load null pointer dereferenceggml-org whisper.cpp
CVE-2025-53630Integer Overflow in GGUF Parser can lead to Heap Out-of-Bounds Read/Write in ggufggml-org llama.cpp
CVE-2025-14569ggml-org whisper.cpp common-whisper.cpp read_audio_data use after freeggml-org whisper.cpp
29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.