Vulnerability Description
llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ggml | Llama.Cpp | <= 0.4.0 |
Related Weaknesses (CWE)
References
- https://blog.ph4nt0m.xyz/ko/cves/cve-2026-52132/Third Party Advisory
- https://github.com/ggml-org/llama.cppProduct
FAQ
What is CVE-2026-52132?
CVE-2026-52132 is a vulnerability with a CVSS score of 7.5 (HIGH). llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST reques...
How severe is CVE-2026-52132?
CVE-2026-52132 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-52132?
Check the references section above for vendor advisories and patch information. Affected products include: Ggml Llama.Cpp.