Skip to content
cvellmllama-cppdenial-of-serviceuncontrolled-recursion

llama.cpp json-schema-to-grammar Uncontrolled Recursion DoS

1 min read

Overview

llama.cpp <= b5693 (commit 97f06e9) is vulnerable to denial of service through uncontrolled recursion in common/json-schema-to-grammar.cpp. Passing a deeply nested JSON schema in the json_schema field exhausts the recursion stack and crashes the server.

Details

  • Vulnerable functions: SchemaConverter::visit (line 839), _generate_union_rule (line 339)
  • Entry point: tools/server/server-task.cpp (line 373)
  • Affected path: Only POST /completions. POST /v1/chat/completions routes json_schema through the jinja engine and is not affected.
  • Reproducibility: 100% at recursion depth >= 7000. Confirmed on x86-64 Linux with the default 8 MB thread stack.

NVD

  • CVSS: 7.5 (high)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • CWE: CWE-674 (Uncontrolled Recursion)
  • Attack vector: Network (remote)
  • Published: 2026-09-01 (NVD)

Patch status

  • Unpatched as of the latest release b10405 (2026-08-13). SchemaConverter::visit, _generate_union_rule and get_recursive_refs take no recursion-depth argument, so the uncontrolled recursion remains. The only change to the file since the baseline (b5693) is parse ordering (PR #24835), which is unrelated to recursion control.

References