Overview
When started with the --reranking flag, llama.cpp (up to commit 97f06e9) lets a remote attacker cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST /rerank request.
Details
- Vulnerable locations:
tools/server/server-context.cpp(line 4048) andformat_response_rerankintools/server/server-common.cpp(line 1245) - Precondition: the
--rerankingserver flag (not on by default) - Behavior: the server returns HTTP 500 while processing the request and stays alive rather than crashing outright.
- Reproducibility: 100% when
top_n < 0.
NVD
- CVSS: 7.5 (high)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CWE: CWE-674 (Uncontrolled Recursion) — NVD's classification. This differs from the technical root cause (an integer-handling error from an unvalidated negative
top_n, closer to CWE-190); the CWE-674 label is NVD's own re-classification. - Attack vector: Network (remote)
- Published: 2026-09-01 (NVD)
Patch status
- Unpatched as of the latest release b10405 (2026-08-13). In
server-context.cpp,int top_n = json_value(body, "top_n", ...)has no negative check, sotop_n < 0is passed through unchanged.