Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-107183: llama.cpp can be crashed and manipulated via crafted chat request
CVE-2026-107183 · published 3 days ago
Summary
The open‑source llama.cpp library may let an attacker send a specially formed chat request that causes the server to stop working and potentially change data in memory. This happens because the software frees memory it still needs and then uses it again. Update to the latest version of llama.cpp as soon as possible to stop the risk.
What to do
- Update ggml-org llama.cpp to version b11393 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | ggml-org | llama.cpp | < b11393 |
| Debian:14 | debian | llama.cpp | All versions |
| Ubuntu:26.04:LTS | canonical | llama.cpp | All versions |
Original advisory text
llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser
llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive.
References
- https://github.com/ggml-org/llama.cpp
- https://github.com/ggml-org/llama.cpp/pull/29942
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-1071... Vendor Advisory
- https://github.com/ggml-org/llama.cpp/blob/bed0a856606ee4a24a164066f73d237944703...
- https://github.com/ggml-org/llama.cpp/blob/bed0a856606ee4a24a164066f73d237944703...
- https://nvd.nist.gov/vuln/detail/CVE-2026-107183 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-107183 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-107183 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-107183 Third Party Advisory
- https://github.com/ggml-org/llama.cpp/commit/dbe4c3ed42343f0a7ba0fd7e808ffeaca40...
- https://www.vulncheck.com/advisories/llama-cpp-before-b11393-use-after-free-via-...
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-416Use After Free
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-107183 · NVD
CVE-2026-107183 · MITRE
CVE-2026-107183 · OSV
DEBIAN-CVE-2026-107183 · OSV
UBUNTU-CVE-2026-107183 · OSV
Track software like this
Free during beta