What is CVE-2026-17501?
This vulnerability in ggml-org/llama.cpp commit e15efe0 involves uncontrolled recursion in the transform function of the JSON-Schema-to-GBNF converter, allowing remote attacks. Users are advised to update the repository with the latest security patches.
Azərbaycanca: Bu boşluq ggml-org/llama.cpp-nin e15efe0 versiyasında JSON-Schema-to-GBNF çeviricisinin transform funksiyasında nəzarətsiz rekursiyaya səbəb olur. Bu zəiflik uzaqdan hücuma imkan verir və istifadəçilərə repo-nu ən son təhlükəsizlik yamaları ilə yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which repository and version was CVE-2026-17501 discovered?
This vulnerability was discovered in the ggml-org/llama.cpp repository at commit e15efe0.
What action is recommended to mitigate this vulnerability?
Users are advised to update the repository with the latest security patches.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.