SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86317

MEDIUM · CVSS 5.3 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in the RPC Server component of ggml-org llama.cpp versions up to 0.4.0, specifically affecting the `rpc_server::deserialize_tensor` function. This flaw allows remote attackers to manipulate the `ne` argument, leading to a reachable assertion that could potentially disrupt service. Organizations using this software should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86317
Severity
MEDIUM
CVSS
5.3
EPSS
0.40%
GitHub

Original NVD Description

A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component RPC Server. Performing a manipulation of the argument ne results in reachable assertion. The attack is possible to be carried out remotely. The reported GitHub issue was closed automatically due to inactivity.