Multiple high-severity vulnerabilities were disclosed in ggml-org/llama.cpp, including CVE-2026-43622 and CVE-2026-70638, both affecting builds b1886 through b7445 and semver releases 0.9.0 through 0.17.1. The flaws are concentrated in the LLaMA-Android JNI wrapper in llama-android.cpp: one issue stems from a malloc()/delete mismatch in new_1batch() and free_1batch(), causing a double free and heap metadata corruption, while the other arises from an unchecked integer multiplication involving n_seq_max, leading to insufficient heap allocation and possible heap corruption. Both bugs can crash Android applications using the binding and may enable arbitrary code execution depending on runtime conditions; patched release b7446 is cited as the fix point.
The disclosures were accompanied by a public patch repository from Cyera Research, which said it reported 10 llama.cpp vulnerabilities between 2025 and 2026, covering issues such as integer overflow, integer underflow, buffer overflow, use-after-free, unbounded task creation, and an Android JNI race condition. Cyera said earlier advisories and a patch pull request were closed without fixes being merged, after which VulnCheck assigned 10 CVE IDs, including replacement identifiers CVE-2026-70638, CVE-2026-70639, and CVE-2026-70640. The reported flaws carry CVSS scores ranging from 7.3 to 9.2, underscoring ongoing supply-chain risk for developers embedding llama.cpp in Android and other AI-enabled applications.

Track how attackers are adapting to this technology.
10 events from the most recent confirmed update back to the earliest known activity.
A public disclosure detailed six critical and high-severity llama.cpp vulnerabilities, including CVE-2026-43627, CVE-2026-43629, CVE-2026-43631, CVE-2026-43632, CVE-2026-43628, and CVE-2026-70640, affecting builds from b1283 through b9058 depending on the flaw. The disclosure said Cyera released community patches for all six issues and that no official vendor fixes were available at publication.
On August 6, 2026, disclosure@vulncheck.com received the CVE entry for CVE-2026-70638. The record describes an integer overflow in llama.cpp's LLaMA-Android JNI wrapper new_1batch() function affecting builds b1886 through b7445 and versions 0.9.0 through 0.17.1.
VulnCheck received a new CVE record for CVE-2026-43622 on August 6, 2026. The record describes a double free in the LLaMA-Android JNI wrapper affecting llama.cpp builds b1886 through b7445 and semver releases 0.9.0 through 0.17.1.
Cyera Research disclosed security patches for multiple unpatched llama.cpp vulnerabilities and published them in a GitHub repository so users and downstream projects could protect themselves. The repository documents the affected flaws and replacement CVE mappings.
Cyera Research reported 10 vulnerabilities to the llama.cpp project between July 2025 and June 2026 through GitHub Security Advisories and MITRE. The disclosure says the maintainer closed all advisories without fixes or CVE assignment.
Cyera submitted a public pull request with patches for the reported llama.cpp vulnerabilities in June 2026. The source states the project later closed the patch PR without merging it.
In May 2026, VulnCheck allocated 10 CVE IDs for the llama.cpp vulnerabilities after the vendor and MITRE did not complete assignment. The disclosure says this included replacement IDs CVE-2026-70638, CVE-2026-70639, and CVE-2026-70640 for earlier identifiers.
From January through May 2026, Cyera submitted four additional vulnerability advisories affecting llama.cpp. According to the disclosure, all of them were closed without fixes.
In October 2025, Cyera contacted MITRE to obtain CVE assignments for the reported llama.cpp issues. The source says seven request IDs were received, but no CVEs were assigned at that stage.
Cyera Research reported the first of 10 llama.cpp vulnerabilities through a GitHub Security Advisory in July 2025. This began a disclosure process that later expanded across multiple reports.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.