CVE-2026-17500: Ggml-Org Llama.cpp

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.

Affected products

  • Ggml-Org Llama.cpp: version d006858 only; version e15efe0 only

Published 2026-07-27. Last modified 2026-07-27.