Unauthenticated RCE via GRAPH_COMPUTE buffer=0 bypass in llama.cpp RPC backend
llama.cpp security advisories
All 13 advisories llama.cpp has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 1312 carry a CVE
- critical
- 2
- high
- 6
- medium
- 4
- low
- 1
- Fix in the archive
- 0of 13 matched to a release
- Oldest
- 26 Apr 20242.3 years ago
13 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productHeap Buffer Overflow via Integer Overflow in GGUF Tensor Parsing
Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 Fix
Out-of-bounds Write in llama.cpp llama-server
Integer Overflow in GGUF Parser can lead to Heap Out-of-Bounds Read/Write in gguf
Heap-based Buffer Over-read in llama_model_load
Tokenizer signed vs. unsigned heap overflow
Buffer Overflow in llama.cpp via Malicious GGUF Model – Exploitable via Vocabulary Loading (`llama_vocab::impl::token_to_piece`)
global-buffer-overflow in ggml_type_size
Arbitrary Address Read in rpc_server::get_tensor
Write-what-where in rpc_server::set_tensor
Null pointer dereference in gguf_init_from_file
Use of Uninitialized Variable Vulnerability in gguf_init_from_file