PatchSiren

ggml-org CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ggml-org CVE published 2026-07-27

CVE-2026-17501

A flaw has been found in ggml-org llama.cpp e15efe0, affecting the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes allocation of resources. The attack may be initiated remotely. The CVSS score is 6.9, indicating a medium severity. Users and administrators of ggml-org llama.cpp e15efe0 should review the vulnerability [truncated]

MEDIUM ggml-org CVE published 2026-07-27

CVE-2026-17500

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T01:16:26.380Z and has not been modified since then. This vulnerability affects ggml-org llama.cpp installations, specifically the function _visit_pattern of the file common/json-schema-to-grammar.cpp, leading to a null pointer dereference. The attack can be launched remotely with a CVSS score of [truncated]