THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-43628 (HIGH 7.8) — llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry_allowed_length set to INT32_MIN to the /v1

[NVD] CVE-2026-43628 (HIGH 7.8) — llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry_allowed_length set to INT32_MIN to the /v1

lownvdPublished 2026-08-06

CVE-2026-43628 CVSS: 7.8 HIGH Published: 2026-08-06T22:17:05.777

llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry_allowed_length set to INT32_MIN to the /v1/completions or /v1/chat/completions endpoints. Attack

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-43628