🚨 CVE-2026-52132
llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank.
🎖@cveNotify

Ph4nt0m
llama.cpp /rerank 음수 top_n 서비스 거부
--reranking 플래그로 실행된 llama.cpp는 POST /rerank의 음수 top_n 값을 통해 원격 서비스 거부 (std::bad_alloc, HTTP 500)에 취약합니다.
September 1, 2026 39