CVE-2026-52132
llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank.
- Published Sep 1, 2026
- CVSS 7.5 high
- 0.6% chance of exploitation in the next 30 days (EPSS)