vciy

CVEs we hold for Ggml-org

Records whose assigning authority named Ggml-org as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-86317ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertionggml-org llama.cpp
CVE-2026-78148ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp graph_compute null pointer dereferenceggml-org llama.cpp
CVE-2026-78147ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp deserialize_tensor deserializationggml-org llama.cpp
CVE-2026-70640llama.cpp b1886–b7445 Race Condition Use-After-Free via llama-android.cppggml-org llama.cpp
CVE-2026-70639llama.cpp b1886–b7445 Null Pointer Dereference DoS via llama-android.cppggml-org llama.cpp
CVE-2026-70638llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cppggml-org llama.cpp
CVE-2026-43632llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpointsggml-org llama.cpp
CVE-2026-43631llama.cpp b7492–b9060 Use-After-Free RCE via llama-serverggml-org llama.cpp
CVE-2026-43630llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosureggml-org llama.cpp
CVE-2026-43629llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restoreggml-org llama.cpp
CVE-2026-43628llama.cpp b3978–b9058 Integer Underflow via DRY Samplerggml-org llama.cpp
CVE-2026-43627llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Functionggml-org llama.cpp
CVE-2026-43622llama.cpp b1886–b7445 Double Free via llama-android.cppggml-org llama.cpp
CVE-2026-39909llama.cpp Use-After-Free in RPC GRAPH_RECOMPUTE Handlerggml-org llama.cpp
CVE-2026-34159llama.cpp: Unauthenticated RCE via GRAPH_COMPUTE buffer=0 bypass in llama.cpp RPC backendggml-org llama.cpp
CVE-2026-33298llama.cpp has a Heap Buffer Overflow via Integer Overflow in GGUF Tensor Parsingggml-org llama.cpp
CVE-2026-27940llama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 Fixggml-org llama.cpp
CVE-2026-21869llama.cpp has Out-of-bounds Write in llama-serverggml-org llama.cpp
CVE-2026-2069ggml-org llama.cpp GBNF Grammar llama-grammar.cpp llama_grammar_advance_stack stack-based overflowggml-org llama.cpp
CVE-2026-18581ggml-org llama.cpp Jinja Minja Template parser.cpp assertionggml-org llama.cpp
CVE-2026-17513ggml-org whisper.cpp ggml.c ggml_ftype_to_ggml_type assertionggml-org whisper.cpp
CVE-2026-17512ggml-org whisper.cpp log_mel_spectrogram out-of-boundsggml-org whisper.cpp
CVE-2026-17501ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform recursionggml-org llama.cpp
CVE-2026-17500ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereferenceggml-org llama.cpp
CVE-2026-10298ggml-org whisper.cpp ggml.c whisper_model_load null pointer dereferenceggml-org whisper.cpp
CVE-2025-53630Integer Overflow in GGUF Parser can lead to Heap Out-of-Bounds Read/Write in ggufggml-org llama.cpp
CVE-2025-52566llama.cpp tokenizer signed vs. unsigned heap overflowggml-org llama.cpp
CVE-2025-49847llama.cpp Vulnerable to Buffer Overflow via Malicious GGUF Modelggml-org llama.cpp
CVE-2025-14569ggml-org whisper.cpp common-whisper.cpp read_audio_data use after freeggml-org whisper.cpp

29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.