ggml-org vulnerabilities
5 CVEs tracked
The ggml-org vendor appears in our recent reporting primarily through its two popular open-source projects: llama.cpp and whisper.cpp. A total of five new vulnerabilities have been identified across these projects, with three of them being remotely exploitable. Notably, CVE-2026-17501 involves uncontrolled recursion that could lead to remote code execution, and CVE-2026-17500 is a null pointer dereference flaw. Defenders should urgently apply the provided patches for CVE-2026-17501, CVE-2026-17500, CVE-2026-17513, CVE-2026-17512, and CVE-2026-18581, paying special attention to auditing externally-facing JSON-schema-to-grammar and Jinja template parsing functionalities.
Azərbaycanca: ggml-org təşkilatı son hesabatlarımızda əsasən iki məşhur açıq mənbəli layihəsi – llama.cpp və whisper.cpp – ilə görünür. Bu layihələrdə ümumilikdə beş yeni zəiflik aşkar edilib ki, onlardan üçü uzaqdan istismar edilə bilən xarakter daşıyır. Xüsusilə, CVE-2026-17501 uzaqdan kod icrasına səbəb ola biləcək nəzarətsiz rekursiya, CVE-2026-17500 isə null pointer dereference zəiflikləri ilə diqqət çəkir. Müdafiəçilər CVE-2026-17501, CVE-2026-17500, CVE-2026-17513, CVE-2026-17512 və CVE-2026-18581 üçün təqdim olunan yamaları təcili olaraq tətbiq etməli, xüsusən də xarici girişə açıq olan JSON-schema-to-grammar və Jinja şablon funksionallıqlarını audit etməlidirlər.
This vendor's CVEs5
This hub is built from skopnix's own reporting on ggml-org: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.