Database/AI/ML frameworks & serving

llama-server (KV cache state restore): Heap buffer overflow in `state_read_data`
CVSS 8.1CVE-2026-43629AI/ML frameworks & servingcurated
Impact
Heap buffer overflow in state_read_data
Who can reach it
Attacker-supplied KV/session state file restored by the server
What to do
Rebuild; session-state restore is an untrusted-input parser
References
Related entries
- llama-server (tokenization endpoints): Use-after-free across six tokenization endpointsCVE-2026-43632 · llama-server (tokenization endpoints)High
- NVIDIA NemoClaw: installation process executes untrusted codeCVE-2026-65081 · NVIDIA NemoClaw for Linux (installer)High
- NVIDIA NemoClaw: deployment process fails to validate certificates properlyCVE-2026-65084 · NVIDIA NemoClaw for Linux (deployment process, TLS certificate validation)High
- NVIDIA NemoClaw: weak authentication in the remote-access helper workflowCVE-2026-65098 · NVIDIA NemoClaw for Linux (remote-access helper workflow)High
- NVIDIA NemoClaw: inference service comes up without authentication, reachable from the adjacent networkCVE-2026-65105 · NVIDIA NemoClaw for Linux (inference server setup)High
- Bifrost LLM gateway: unauthenticated plugin API loads a remote shared object, giving RCE on dynamic buildsCVE-2026-86242 · Bifrost LLM gateway (HTTP transport /api/plugins shared-object loader)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.