CVE-2026-34159Exploit(ggml / llama.cpp)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch ggml llama.cpp systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthenticated attacker can read and write arbitrary process memory via crafted GRAPH_COMPUTE messages. Combined with pointer leaks from ALLOC_BUFFER/BUFFER_GET_BASE, this gives full ASLR bypass and remote code execution. No authentication required, just TCP access to the RPC server port. This issue has been patched in version b8492.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • llama.cpp

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 15 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 13 signals
  • Disclosure: 4 classified signals
  • Peaked 5d ago at 3 mentions (2026-04-25); latest day: 1
  • 15 total mentions across 9 days

Affected systems

Vendors
Products
llama.cpp

Deep dive

Activity timeline15 mentions / 9d
01223Mentions · 2026-04-01: 1Mentions · 2026-04-02: 2Mentions · 2026-04-24: 1Mentions · 2026-04-25: 3Mentions · 2026-04-26: 2Mentions · 2026-04-27: 1Mentions · 2026-05-03: 1Mentions · 2026-05-12: 3Mentions · 2026-05-31: 1PoC Mentioned / Linked · 2026-04-24: 1PoC Mentioned / Linked · 2026-04-25: 3PoC Mentioned / Linked · 2026-04-26: 1PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-05-31: 1Exploit Tool / Code · 2026-04-24: 1Exploit Tool / Code · 2026-04-25: 2Exploit Tool / Code · 2026-04-26: 1Exploit Tool / Code · 2026-04-27: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-05-03: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 2Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 3Technical Details · 2026-04-26: 2Technical Details · 2026-05-03: 1Technical Details · 2026-05-12: 2Technical Details · 2026-05-31: 104-0104-0204-2404-2504-2604-2705-0305-1205-31
Signal classification5 categories
Exploit
533.3%
Disclosure
426.7%
Patch
213.3%
PoC
213.3%
General
213.3%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-011
Disclosure1
2026-04-022
Disclosure1Patch1
2026-04-241
Exploit1
2026-04-253
Exploit2PoC1
2026-04-262
Disclosure1Exploit1
2026-04-271
Exploit1
2026-05-031
Patch1
2026-05-123
Disclosure1General2
2026-05-311
PoC1
Full discourse15 posts
  • Hassan Ali@casp3r0x0
    Exploit

    Lets write an 1-day Zero Click #exploit ! for CVE-2026-34159 llama.cpp and hack into #AI infrastructure ! blog post : https://www.pwntricks.com/ZeroClick-RCE-CVE-2026-34159-llama.cpp exploit https://github.com/casp3r0x0/CVE-2026-34159 #Cyber #Security #OSCP #ExploitDevelopment https://t.co/K8vVCsITCl

    Post summary

    The tweet promotes a zero‑click exploit for CVE‑2026‑34159, providing a blog post and GitHub repository with PoC code, but no evidence of active exploitation or patch information.

    266132424119.0K
    222 followersView on X
  • NullSecurityX@NullSecurityX
    Exploit

    Exploiting llama.cpp’s RPC Server - From Null Buffer to RCE Against PIE + Full RELRO + NX | CVE-2026-34159: The vulnerability is a one-line logic bug in the RPC server’s tensor deserialization pipeline. Youtube: https://www.youtube.com/@NullSecurityX Blog: https://www.pwntricks.com/ZeroClick-RCE-CVE-2026-34159-llama.cpp https://t.co/9TzOyEpTbM

    Post summary

    The post discloses a logic‑bug‑driven RCE in llama.cpp’s RPC server, with linked videos and a blog that provide a proof‑of‑concept exploit.

    243023412219.6K
    12.3K followersView on X
  • KF@d0tslash
    Exploit

    "0 Click RCE exploit for CVE-2026-34159 Lama.cpp RPC server version b8487" https://github.com/casp3r0x0/CVE-2026-34159 https://t.co/qlqiseuhrB

    Post summary

    A zero‑click remote code execution exploit for CVE‑2026‑34159 has been released, with code available on GitHub and no indicators of active exploitation or available patches.

    1210965912.1K
    11.3K followersView on X
  • KF@d0tslash
    Exploit

    "CVE-2026-34159: Exploiting llama.cpp’s RPC Server - From Null Buffer to RCE Against PIE + Full RELRO + NX" https://www.pwntricks.com/ZeroClick-RCE-CVE-2026-34159-llama.cpp https://t.co/oKYETO7zGt

    Post summary

    The tweet promotes a ZeroClick RCE demonstration for CVE‑2026‑34159 in llama.cpp, providing PoC and exploit details but making no claim of live exploitation or available fixes.

    06111612.7K
    11.3K followersView on X
  • Blue Team News@blueteamsec1
    PoC

    CVE-2026-34159: Exploiting llama.cpp’s RPC Server - From Null Buffer to RCE Against PIE + Full RELRO + NX http://dlvr.it/TSpK2r #cyber #threathunting #infosec

    Post summary

    The post announces CVE‑2026‑34159, describing a null‑buffer RCE against llama.cpp’s RPC server and providing a link for further details or a proof‑of‑concept, but it does not mention active exploitation, a patch, or debunking.

    02020752
    56.6K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-34159: llama.cpp RPC backend has an unauthenticated, no-bounds-check RCE. Zero buffer field in deserialize_tensor() allows arbitrary memory read/write. No auth, low complexity, CVSS 9.8. Patch to b8492 immediately. #cybersecurity #infosec #business #devsecops info:

    Post summary

    This post announces a high‑severity unauthenticated RCE in llama.cpp’s RPC backend, provides technical details, and notes that a patch (commit b8492) is immediately available.

    10010130
    889 followersView on X
  • FAMASoon@FAMASoon
    PoC

    Zeroclick Rce Cve 2026 34159 Llama.cpp - https://www.pwntricks.com/ZeroClick-RCE-CVE-2026-34159-llama.cpp

    Post summary

    The note points to CVE‑2026‑34159 and a link that appears to host a Proof of Concept for a ZeroClick RCE, but offers no evidence of active exploitation or remediation.

    00002235
    993 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-34159 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post lists CVE‑2026‑34159 with a critical score but provides no exploitation, mitigation, or PoC details.

    1000039
    210 followersView on X
  • Hacking Team@HackingTeam77
    Exploit

    Lets write an 1-day Zero Click #exploit ! for CVE-2026-34159 llama.cpp and hack into #AI infrastructure ! blog post : https://pwntricks.com/ZeroClick-RCE-CVE-2026-34159-llama.cpp exploit https://github.com/casp3r0x0/CVE-2026-34159 #Cyber #Security #OSCP #ExploitDevelopment SRC:https://x.com/casp3r0x0/status/2047622881635385662?s=20 https://t.co/Zqxpr8olW5

    Post summary

    The post announces a zero-click exploit for CVE-2026-34159 against llama.cpp, offering links to a blog post and a GitHub repository that contain the PoC and exploit code.

    00010400
    1.8K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-34159-ggml-llama-cpp #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text references a CVE (2026-34159) via a link but does not provide explicit details, PoC, exploit, patch information, or evidence of active exploitation.

    0000024
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-34159 (CVSS 9.8) — ggml llama.cpp. CVE: CVE-2026-34159 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces CVE-2026-34159 as a critical vulnerability in ggml llama.cpp, providing its CVSS score and attack vector, but offers no details on exploitation, tools, or remediation.

    0000043
    210 followersView on X
  • Outis@xfeylesof
    Disclosure

    From Null Buffer to RCE Against PIE + Full RELRO + NX | CVE-2026-34159: The vulnerability is a one-line logic bug in the RPC server’s tensor deserialization pipeline. Youtube: http://youtube.com/@NullSecurityX #BugBounty #CyberSecurity

    Post summary

    The post announces the identification of a new logic‑bug vulnerability in an RPC server’s tensor deserialization, marking CVE‑2026‑34159 as disclosed.

    00000219
    1.8K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34159: CRITICAL] Critical vulnerability in llama.cpp prior to version b8492 allows unauthenticated attackers to achieve remote code execution by crafting GRAPH_COMPUTE messages. Patch available in ...#cve,CVE-2026-34159,#cybersecurity https://cvefind.com/CVE-2026-34159

    Post summary

    A critical RCE vulnerability was disclosed in llama.cpp prior to commit b8492; a patch is now available to mitigate the flaw.

    0000031
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34159 - Critical llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An ... https://www.thehackerwire.com/vulnerability/CVE-2026-34159/ https://t.co/u6gyLLYFO8

    Post summary

    The tweet discloses a critical vulnerability (CVE-2026-34159) in llama.cpp where the RPC deserialization function ignores bounds checks, potentially enabling memory corruption.

    0000057
    163 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34159: llama.cpp: Unauthenticated RCE v... Zero bounds checking on buffer=0 tensors turns every llama.cpp RPC server into a memory corruption playground—ASLR bypa... https://zerodaysignal.com/vulnerability/CVE-2026-34159 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑34159, a memory‑corruption based unauthenticated RCE vulnerability in llama.cpp, and links to a zero‑day signal page for more details.

    00000108
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appggmlllama.cpp---

Explore more