CVE-2026-18581
A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/
CVSS
3.3
Bajo
EPSS
0.1%
p2
KEV
—
Exploit Today
0
0-100
Publicado: 3 ago 2026 · Última mod.: 3 ago 2026 · CWE-617
0.1%EPSS · 30 días0.1%
2026-08-032026-08-05
A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. Executing a manipulation with the input {{9|9|{ can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
- drive.proton.mehttps://drive.proton.me/urls/R8D8NGZ6Z0#C2cVZYn5z1Xc
- github.comhttps://github.com/ggml-org/llama.cpp/
- github.comhttps://github.com/ggml-org/llama.cpp/issues/25282
- vuldb.comhttps://vuldb.com/cve/CVE-2026-18581
- vuldb.comhttps://vuldb.com/submit/799118
- vuldb.comhttps://vuldb.com/vuln/385409
- vuldb.comhttps://vuldb.com/vuln/385409/cti
- vuldb.comhttps://vuldb.com/submit/799118
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-714306.2 MED—
———node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V8 returns when the resulting string or buffer exceeds V8's maximum string length. When a global replace uses an output amplifying replacement template, the result can grow quadratically with the input size, and once the result exceeds V8's maximum string length, the unchecked ToLocalChecked call causes a fatal, uncatchable process abort instead of a catchable exception. This issue is fixed in version 1.25.1.5hCVE-2026-673034.3 MED16.2%
——5FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_process_irp_device_control() in channels/serial/client/serial_main.c. When serial device redirection is enabled and a server-controlled IRP_MJ_DEVICE_CONTROL request specifies an unsupported IOCTL with a non-zero OutputBufferLength, CommDeviceIoControl() can fail with BytesReturned = 0, causing the mismatch to trigger the assertion and abort the client process (denial of service).3dCVE-2026-528567.5 ALT26.0%
——8Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.6dCVE-2026-667545.9 MED32.9%
——10Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request whose decoded path matches a configured prefix while the raw percent-encoded path does not, causing the assert! to fail and triggering either a 500 error or full process termination depending on the panic configuration.7dCVE-2026-17574—2.0%
——1HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.7dCVE-2026-175133.3 BAJ1.6%
——0A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. The manipulation of the argument ftype results in reachable assertion. The attack requires a local approach. The project was informed of the problem early through an issue report but has not responded yet.10d