Hi,
The following vulnerabilities were published for llama.cpp.
CVE-2026-17500[0]:
| A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0.
| This affects the function _visit_pattern of the file common/json-
| schema-to-grammar.cpp. The manipulation results in null pointer
| dereference. The attack can be launched remotely. The pull request
| to fix this issue awaits acceptance.
CVE-2026-17501[1]:
| A flaw has been found in ggml-org llama.cpp e15efe0. This
| vulnerability affects the function transform of the file
| common/json-schema-to-grammar.cpp of the component JSON-Schema-to-
| GBNF Conversion. This manipulation causes uncontrolled recursion.
| The attack may be initiated remotely. The pull request to fix this
| issue awaits acceptance.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-17500
https://www.cve.org/CVERecord?id=CVE-2026-17500
[1] https://security-tracker.debian.org/tracker/CVE-2026-17501
https://www.cve.org/CVERecord?id=CVE-2026-17501
Regards,
Salvatore