๐Ÿ” CVE Alert

CVE-2026-43628

HIGH 7.8

llama.cpp b3978โ€“b9058 Integer Underflow via DRY Sampler

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry_allowed_length set to INT32_MIN to the /v1/completions or /v1/chat/completions endpoints. Attackers can exploit this vulnerability to crash the server with SIGSEGV causing denial of service for all connected users, or corrupt token sampling probabilities by reading garbage values from memory before the allocated buffer.

CWE CWE-191 CWE-125
Vendor ggml-org
Product llama.cpp
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for ggml-org llama.cpp

Be the first to know when new high vulnerabilities affecting ggml-org llama.cpp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

ggml-org / llama.cpp
b3978 โ‰ค b9058 0.11.0 โ‰ค 0.17.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Vladimir-tokarev-cyera/llama-cpp-security-patches

Credits

Vladimir Tokarev (@G1ND1L4) - Vulnerability Research Tech Lead, Cyera Ofek Itach (@ofekitach) - Security Research Team Lead, Cyera