CVE-2026-78148: ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp graph_compute null pointer dereference

Published Aug 23, 2026
·
Updated

A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpcserver::graphcompute of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The pull request to fix this issue awaits acceptance.

Affected Software

2 affected components
ggml-org/llama.cpp=bec4772f6
ggml-RPC Server=bec4772f6

Event History

Aug 23, 2026
CVE Published
via MITRE·11:15 PM
Data Sourced
via MITRE·11:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments running the ggml-RPC Server component in ggml-org llama.cpp are exposed. The affected code is rpc_server::graph_compute in ggml/src/ggml-rpc/ggml-rpc.cpp.

2

What does an attacker need to exploit it?

The issue can be attacked remotely and requires no privileges or user interaction according to the supplied severity vector. Exploitation involves manipulating input in a way that triggers a null pointer dereference.

3

What is the likely impact of successful exploitation?

The provided vector indicates an availability impact only, with no stated confidentiality or integrity impact. A successful null pointer dereference may cause the affected service to fail or become unavailable.

4

Is a fix available?

A pull request to fix the issue exists but was awaiting acceptance at the time of the provided information. No accepted fix version is identified.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203