llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank.
References
| Link | Resource |
|---|---|
| https://blog.ph4nt0m.xyz/ko/cves/cve-2026-52132/ | Third Party Advisory |
| https://github.com/ggml-org/llama.cpp | Product |
Configurations
History
No history.
Information
Published : 2026-09-01 18:17
Updated : 2026-09-04 20:15
NVD link : CVE-2026-52132
Mitre link : CVE-2026-52132
CVE.ORG link : CVE-2026-52132
JSON object : View
Products Affected
ggml
- llama.cpp
CWE
CWE-674
Uncontrolled Recursion
