Llama.Cpp
Vendor:
First CVE: Feb 26, 2024 · Active for 2 years
16
Total CVEs
More Total CVEs than 92% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
9.0
Avg CVSS
Higher Avg CVSS than 83% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Llama.Cpp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 26, 2024
2 years ago
Most Recent CVE
Apr 1, 2026
114 days ago
CVE Severity & Scoring
Llama.Cpp16 CVEs
38%
56%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (12.5%)
Network14 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (62.5%)
Unknown0 (0.0%)
Required6 (37.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None16 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34159CRITICAL llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is | Apr 1, 2026 | 9.8 | 36 | NO | NO |
CVE-2024-42479CRITICAL llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address writing. This vulnerability is fixed in b3561. | Aug 12, 2024 | 9.8 | 33 | NO | NO |
CVE-2026-21869CRITICAL llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_discard parameter is parsed directly from JSON input in the llama.cpp server's compl | Jan 8, 2026 | 9.8 | 32 | NO | NO |
CVE-2024-42478CRITICAL llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address reading. This vulnerability is fixed in b3561. | Aug 12, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-21836CRITICAL A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code ex | Feb 26, 2024 | 9.8 | 28 | NO | NO |
CVE-2026-33298HIGH llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory valida | Mar 24, 2026 | 7.8 | 27 | NO | NO |
CVE-2024-21825CRITICAL A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf | Feb 26, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-21802CRITICAL A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code executi | Feb 26, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-27940HIGH llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized | Mar 12, 2026 | 7.8 | 26 | NO | NO |
CVE-2024-23605CRITICAL A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code executi | Feb 26, 2024 | 9.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Llama.Cpp
Top CWEs
Versions
No cataloged versions.