When started with --reranking, llama.cpp lets a remote attacker trigger a denial of service (std::bad_alloc, HTTP 500) via a negative top_n on POST /rerank (CVE-2026-52132).
A crafted GGUF file with an empty metadata key reaches an assertion in llama.cpp's gguf_reader::read and aborts the process. Affects any binary that loads GGUF files (CVE-2026-52131).
A deeply nested JSON schema exhausts the recursion stack in llama.cpp's grammar converter, crashing the server. Only POST /completions is affected (CVE-2026-52130).