CVE-2026-33298 | ggml-org llama.cpp up to 55abc39/up to 55d4206c8 GGUF File Parser ggml_nbytes heap-based overflow (GHSA-96jg-mvhq-q7q7)
A vulnerability categorized as critical has been discovered in ggml-org llama.cpp up to 55abc39/up to 55d4206c8. Affected by this issue is the function ggml_nbytes of the component GGUF File Parser. The manipulation results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2026-33298. The attack must be initiated from a local position. There is no exploit available.
It is advisable to upgrade the affected component.