PT-2026-64821 · Llama.Cpp · Llama.Cpp

·

CVE-2026-17501

·

Published

2026-07-27

·

Updated

2026-07-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions llama.cpp version e15efe0
Description A flaw exists in the JSON-Schema-to-GBNF Conversion component within the transform() function of the common/json-schema-to-grammar.cpp file. This issue allows a remote attacker to trigger an excessive allocation of resources.
Recommendations As a temporary workaround, restrict the use of the transform() function within the JSON-Schema-to-GBNF Conversion component until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Allocation of Resources Without Limits

Improper Resource Release

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17501

Affected Products

Llama.Cpp