Skip to content
cvellmllama-cppdenial-of-service

llama.cpp /rerank Negative top_n Denial of Service

1 min read

Overview

When started with the --reranking flag, llama.cpp (up to commit 97f06e9) lets a remote attacker cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST /rerank request.

Details

  • Vulnerable locations: tools/server/server-context.cpp (line 4048) and format_response_rerank in tools/server/server-common.cpp (line 1245)
  • Precondition: the --reranking server flag (not on by default)
  • Behavior: the server returns HTTP 500 while processing the request and stays alive rather than crashing outright.
  • Reproducibility: 100% when top_n < 0.

NVD

  • CVSS: 7.5 (high)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • CWE: CWE-674 (Uncontrolled Recursion) — NVD's classification. This differs from the technical root cause (an integer-handling error from an unvalidated negative top_n, closer to CWE-190); the CWE-674 label is NVD's own re-classification.
  • Attack vector: Network (remote)
  • Published: 2026-09-01 (NVD)

Patch status

  • Unpatched as of the latest release b10405 (2026-08-13). In server-context.cpp, int top_n = json_value(body, "top_n", ...) has no negative check, so top_n < 0 is passed through unchanged.

References