Skip to content

Crucible Findings

This page lists selected public results from Crucible campaigns: assigned CVEs and upstream fixes whose disclosure is complete enough to cite. The current workflow requires replay and source review before naming a finding. The separate disclosure-ledger audit is what determines whether an historical filing's exact frames, lines, build, CWE, and score provenance can be reconstructed; a row on this page is not a substitute for that audit.

Disclosure policy

Crucible follows coordinated disclosure. A finding appears here only when a citable public report, advisory, or upstream fix is available; CVE assignment alone does not make a finding public. Additional findings under coordinated disclosure are not detailed until that process completes. See Responsible Disclosure.

Prior art

For previously-published vulnerabilities across this ecosystem (found by other researchers), which map the surface Crucible targets, see Known CVEs.


Summary

18 CVEs reserved/assigned
17 Public CVE records
211 Research findings
71 Named projects

Latest CVE row-level record check: 2026-10-04; earlier rows retain their own dates. Research breadth is the audited 2026-09-07 snapshot: a finding is a documented research case, and a named project is a distinct primary target repository. The snapshot includes independent rediscoveries and robustness observations at differing evidence levels; its totals do not imply novelty, vendor acceptance, or a current inventory.

The CVE cards come from the CVE ledger. The research cards are a dated September 7, 2026 snapshot of documented research breadth; the counting methodology explains the units and private-audit boundary. The corpus includes independently rediscovered known defects, robustness observations, and source-inspected or reduced-program cases with differing evidence levels. Inclusion does not establish novelty, vendor acceptance, or validation through a real product path. The remediation examples below are selected public results, not a generated total; see Evidence and Validation.

The publicly resolved examples span heap out-of-bounds reads and writes, integer overflows leading to unbounded allocation, out-of-bounds index panics, and reachable assertions.

Severity labels are intentionally omitted from the remediation tables. Their CWE values are Crucible taxonomy hints, not assigner assessments; the generated CVE catalog is the source that keeps proposed and assigner provenance separate.


Assigned CVEs

The generated CVE catalog is the canonical public list. It distinguishes assigned records from records that are actually public and preserves our proposed score separately from the assigner's assessment.

For the ONNX heap over-read, see the source-bound CVE-2026-14647 mechanism diagram. The two ggml RPC records assigned in August 2026 have their own plates: CVE-2026-78147, a controlled indirect call, and CVE-2026-78148, a null graph-node dereference. The first plate describes its standalone public witness: a client-chosen call target and one argument, followed by process termination. September added public assigner records for GPTQModel finding 126, CVE-2026-86288, and Ollama finding 038, CVE-2026-86289; the generated catalog records their current publication state.


Fixed upstream

stable-diffusion.cpp

Four findings in stable-diffusion.cpp model and imatrix loading, all fixed by the maintainer.

ID Witnessed primitive Taxonomy hint Site Issue / Fix
097 Heap out-of-bounds write in the imatrix loader (a duplicate tensor name skips a resize, so the accumulation loop writes past a smaller-sized vector) CWE-787, CWE-1284 src/runtime/imatrix.cpp load_imatrix #1749 + PR #1750 (merged)
015 Uncaught JSON exception to process crash CWE-248 is_safetensors_file() #1395
029 Reachable assertion to process abort CWE-617 init_from_safetensors_file() #1396
030 Unbounded allocation to OOM crash CWE-789 GGUFReader::read_metadata() #1397

015, 029, and 030 were fixed in one hardening PR (#1404). 097 is the first memory-corruption finding of the four, a heap out-of-bounds write; its fix is merged. Its public GitHub advisory carries CVE-2026-70659. At the October 4 ledger check, the CVE List record was still pending; the generated catalog distinguishes the published advisory from that pending record.

ONNX Runtime

ID Witnessed primitive Taxonomy hint Site Issue / Fix
067 Unbounded output allocation (OOM) in constant folding CWE-770 ConstantOfShape constant folding #28730 + PR #28751 (merged)

TensorFlow Lite

ID Witnessed primitive Taxonomy hint Site Issue / Fix
022 Out-of-bounds read from unverified FlatBuffer offsets CWE-125 BuildFromAllocation / ValidateModelBuffers #115308 + PR #121112 (merged)

mistral.rs

ID Witnessed primitive Taxonomy hint Site Issue / Fix
081 Out-of-bounds index panic (unvalidated GGUF special-token ids used to index the vocabulary) CWE-125 GGUF token-id load #2225 + PR #2282 (merged)

Ollama

ID Witnessed primitive Taxonomy hint Issue / Fix
037 Uncontrolled memory allocation in the GGUF parser CWE-770 #17032
038 Integer-underflow panic on a GGUF v1 string CWE-191 #17033, fixed by PR #17062, CVE-2026-86289 / VDB-399448
065 Runtime panic on a malformed registry WWW-Authenticate header CWE-129 #17034

tract

ID Witnessed primitive Taxonomy hint Site Fix
082 (residual) Integer overflow to unbounded allocation in the NNEF tensor reader CWE-190, CWE-789 read_block_quant_value sonos/tract#2425 (merged), a fix authored by the Crucible project

GPTQModel

ID Witnessed primitive Taxonomy hint Site Issue / Fix
126 Device out-of-bounds read from an unchecked checkpoint g_idx CWE-125 Triton dequantization kernel #2949 + PR #2950 (merged), CVE-2026-86288 / VDB-399447

The differential, in one finding

The recurring tell across these bugs is a sibling that gets it right. Finding 097 is the clean example. The imatrix loader has two entry points that both read the same untrusted file:

  • collect_imatrix checks that a repeated tensor entry has a consistent value count before it writes.
  • load_imatrix, a few functions away, does not. A duplicate name skips the resize, and the accumulation loop writes past the end of a smaller vector.

The maintainer's own sibling path is the specification for the fix, and the merged patch (#1750) is exactly that check, ported to the vulnerable path. This is why a differential turns a fuzzing crash into a directed, explainable finding: the divergence proves the missing check is an oversight, not a design decision.


Discovery method

The current acceptance workflow is: run a native or offline campaign with process evidence, replay the input, group it under the appropriate identity, read the target source, establish the primitive, and re-verify against a clean pinned build before naming it. Crucible's structure-aware mutation engine produces files intended to survive selected format gates and reach parser, loader, and kernel code; actual reach is measured by the target harness rather than inferred from the mutation.