CVE-2026-86317
Dashboard / Vulnerabilities / CVE-2026-86317
CVE-2026-86317
Summary: ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertion
Details: A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component RPC Server. Performing a manipulation of the argument ne results in reachable assertion. The attack is possible to be carried out remotely. The reported GitHub issue was closed automatically due to inactivity.
References: https://github.com/ggml-org/llama.cpp/, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86317.json, https://nvd.nist.gov/vuln/detail/CVE-2026-86317, https://vuldb.com/cve/CVE-2026-86317, https://vuldb.com/submit/908271, https://vuldb.com/vuln/399508, https://github.com/ggml-org/llama.cpp/issues/25288, https://vuldb.com/vuln/399508/cti
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
