


Perceptive Security
SOC/SIEM Consultancy

llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.
Published:
1 september 2026 om 00:00:00
Alert date:
1 september 2026 om 22:02:06
Source:
nvd.nist.gov
Emerging Technologies, Security Tools
CVE-2026-52130 affects llama.cpp versions up to and including build b5693. The vulnerability exists in the file common/json-schema-to-grammar.cpp and is classified as Uncontrolled Recursion. Exploitation of this vulnerability can result in a denial of service condition. The issue is tracked in the NVD and has been documented with a blog post and the official llama.cpp GitHub repository. llama.cpp is a widely used open-source library for running large language models locally. The vulnerability could be triggered by crafted input that causes unbounded recursive function calls, exhausting stack resources. Users are advised to update to a version beyond b5693 to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
llama.cpp b5693 and before
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-52130
https://blog.ph4nt0m.xyz/ko/cves/cve-2026-52130/
https://github.com/ggml-org/llama.cpp
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
