Crucible CVE Catalog¶
18 CVEs reserved or assigned; 17 have a public record. 15 of those are in the CVE List; 2 are published by their assigners and awaiting propagation, and their identifiers link to the assigners' records while the CVE List records are pending. 1 assigned identifier has no public record and is omitted from the table.
This catalog is generated from reports/cve-ledger.yaml. It keeps the observed primitive, our proposed score, and the assigner's assessment separate; a CWE or score is never used as a substitute for what the witness demonstrated.
Latest row-level record check in the source ledger: 2026-10-04. Individual rows may have earlier check dates.
| CVE | Project | Witnessed primitive | Our proposal | Assigner assessment | Record | Report / fix | Visual |
|---|---|---|---|---|---|---|---|
| CVE-2025-66455 | InternLM/lmdeploy | untrusted-deserialization-rce | 9.8 Critical (submitted) | v3.1 9.8 Critical | CVE List | Report / fix | No visual |
| CVE-2026-10298 | whisper.cpp | null-dereference + reachable-assertion | 5.5 Medium | v3.1 3.3 / v4.0 4.8 | CVE List | Report / fix | No visual |
| CVE-2026-14647 | onnx | heap-oob-read | 7.5 High | v3.1 4.3 / v4.0 5.3 | CVE List | Report / fix | Mechanism |
| CVE-2026-17500 | llama.cpp | null-dereference | 7.5 High | v3.1 5.3 / v4.0 6.9 | CVE List | Report / fix | No visual |
| CVE-2026-17501 | llama.cpp | stack-exhaustion | 7.5 High | v3.1 5.3 / v4.0 6.9 | CVE List | Report / fix | Mechanism |
| CVE-2026-17512 | whisper.cpp | heap-oob-read | 8.1 High | v3.1 3.3 / v4.0 4.8 | CVE List | Report / fix | Mechanism |
| CVE-2026-17513 | whisper.cpp | reachable-assertion | 5.5 Medium | v3.1 3.3 / v4.0 4.8 | CVE List | Report / fix | No visual |
| CVE-2026-18581 | llama.cpp | reachable-assertion | 7.5 High | v3.1 3.3 / v4.0 4.8 | CVE List | Report / fix | No visual |
| CVE-2026-70659 | stable-diffusion.cpp | heap-oob-write | ~7.5-8 High | v3.1 7.8 High | GitHub (CVE List pending) | Report / fix | No visual |
| CVE-2026-75090 | EricLBuehler/mistral.rs | oob-index-panic | 7.5 High | v3 base 4.3 / temp 3.9 (VulDB meta) | CVE List | Report / fix | No visual |
| CVE-2026-75093 | sonos/tract | panic | 7.5 High | v3 base 4.3 / temp 3.9 (VulDB meta) | CVE List | Report / fix | No visual |
| CVE-2026-78147 | llama.cpp (ggml-rpc) | controlled-indirect-call | 9.8 Critical (proposed, not ratified) | v3.1 7.3 / v4.0 6.9 | CVE List | Report / fix | Mechanism |
| CVE-2026-78148 | llama.cpp (ggml-rpc) | null-dereference | 7.5 High | v3.1 5.3 / v4.0 6.9 | CVE List | Report / fix | Mechanism |
| CVE-2026-84286 | turboderp-org/exllamav3 | oob-function-pointer-dispatch | High (proposed, not ratified) | Not recorded | CERT/CC (CVE List pending) | Report / fix | No visual |
| CVE-2026-86288 | ModelCloud/GPTQModel | device-oob-read | 6.1 Medium | v3.1 6.3 / v4.0 5.3 | CVE List | Report / fix | No visual |
| CVE-2026-86289 | ollama/ollama | integer-underflow-panic | 7.5 High | v3.1 4.3 / v4.0 5.3 | CVE List | Report / fix | No visual |
| CVE-2026-86317 | llama.cpp (ggml-rpc) | assertion-abort | 7.5 High | v3.1 5.3 / v4.0 6.9 | CVE List | Report / fix | No visual |
Reading the catalog¶
- Witnessed primitive comes from the reproducer and trace, not the submitted or assigned CWE.
- Our proposal is the researcher's pre-ratification assessment retained for provenance.
- Assigner assessment is what the CNA or advisory authority recorded publicly.
- Record names the register the identifier resolves in. A record published by its assigner is public and citable; the CVE List mirrors it on its own schedule, and until it does,
cve.orgreturns 404 for that identifier. - Assigned identifiers without public records appear only in aggregate counts, not in the table.
Browse the CVE mechanism visual library for source-bound explanations.