Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-107183: llama.cpp can be crashed and manipulated via crafted chat request

CVE-2026-107183 · published 3 days ago
Summary

The open‑source llama.cpp library may let an attacker send a specially formed chat request that causes the server to stop working and potentially change data in memory. This happens because the software frees memory it still needs and then uses it again. Update to the latest version of llama.cpp as soon as possible to stop the risk.

What to do
  • Update ggml-org llama.cpp to version b11393 or later.
Affected software
Ecosystem VendorProductAffected versions
– ggml-org llama.cpp < b11393
Debian:14 debian llama.cpp All versions
Ubuntu:26.04:LTS canonical llama.cpp All versions
Original advisory text
llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser
llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-416Use After Free
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta