CVE-2026-21869 | ggml-org llama.cpp up to 55d4206c8 Completion Endpoint n_discard out-of-bounds write (GHSA-8947-pfff-2f3c / Nessus ID 284799)
A vulnerability, which was classified as critical, was found in ggml-org llama.cpp up to 55d4206c8. This issue affects some unknown processing of the component Completion Endpoint. Such manipulation of the argument n_discard leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2026-21869. The attack can be launched remotely. No exploit exists.