Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 23 Aug 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params results in deserialization. The attack may be initiated remotely. This vulnerability is distinct from CVE-2026-34159 (GHSA-j8rj-fmpv-wcxw, PR #20908), which only added a buffer==nullptr rejection in create_node() and does not validate op or op_params. The reported GitHub issue was closed automatically due to inactivity. | |
| Title | ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp deserialize_tensor deserialization | |
| First Time appeared |
Ggml-org
Ggml-org llama.cpp |
|
| Weaknesses | CWE-20 CWE-502 |
|
| CPEs | cpe:2.3:a:ggml-org:llama.cpp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ggml-org
Ggml-org llama.cpp |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-23T23:00:13.111Z
Reserved: 2026-08-23T06:39:05.390Z
Link: CVE-2026-78147
No data.
Status : Deferred
Published: 2026-08-23T23:16:46.243
Modified: 2026-08-24T16:40:53.647
Link: CVE-2026-78147
No data.
OpenCVE Enrichment
Updated: 2026-08-24T00:30:10Z