CVE-2026-17501: Ggml-Org Llama.cpp
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes uncontrolled recursion. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
Affected products
- Ggml-Org Llama.cpp: version e15efe0 only
Published 2026-07-27. Last modified 2026-07-29.