Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Denial of Service via Negative top_n Value in llama.cpp Reranking Endpoint | |
| Weaknesses | CWE-20 |
Wed, 02 Sep 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ggml-org
Ggml-org llama.cpp |
|
| Vendors & Products |
Ggml-org
Ggml-org llama.cpp |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-01T17:24:36.476Z
Reserved: 2026-06-08T00:00:00.000Z
Link: CVE-2026-52132
No data.
Status : Received
Published: 2026-09-01T18:17:43.823
Modified: 2026-09-01T18:17:43.823
Link: CVE-2026-52132
No data.
OpenCVE Enrichment
Updated: 2026-09-02T01:15:05Z