CVE-2026-17513
A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. Th
CVSS
3.3
Low
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Jul 27, 2026 · Last modified: Jul 27, 2026 · CWE-617
Not enough EPSS history yet.
A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. The manipulation of the argument ftype results in reachable assertion. The attack requires a local approach. The project was informed of the problem early through an issue report but has not responded yet.
- github.comhttps://github.com/ggml-org/whisper.cpp/
- github.comhttps://github.com/ggml-org/whisper.cpp/issues/3924
- vuldb.comhttps://vuldb.com/cve/CVE-2026-17513
- vuldb.comhttps://vuldb.com/submit/799055
- vuldb.comhttps://vuldb.com/vuln/383383
- vuldb.comhttps://vuldb.com/vuln/383383/cti
- github.comhttps://github.com/ggml-org/whisper.cpp/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-17574——
———HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.6hCVE-2026-458157.5 HIG29.8%
——9Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.
Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.8hCVE-2026-97376.5 MED14.5%
——4During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure.4dCVE-2026-130734.3 MED11.7%
——4An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issue stems from an internal engine selection inconsistency triggered by a specific combination of aggregation options.4dCVE-2026-13058—13.4%
——4An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of required fields. The issue stems from inconsistent validation across related transaction command parameters, resulting in a fatal internal invariant failure and denial of service.4dCVE-2026-130556.5 MED21.1%
——6The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. The user must be able to run an aggregation pipeline.4d