SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78148

MEDIUM · CVSS 5.3 EPSS 0.54% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability in the ggml-RPC Server component of ggml-org llama.cpp can lead to a null pointer dereference, potentially allowing remote attackers to disrupt service. Organizations utilizing this software should prioritize patching this issue, as it poses a medium-level risk that could affect application stability and availability. Immediate attention is recommended for those running affected versions to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78148
Severity
MEDIUM
CVSS
5.3
EPSS
0.54%

Original NVD Description

A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The pull request to fix this issue awaits acceptance.