Use-After-Free and Double Free Vulnerability in llama.cpp by ggml-org
CVE-2026-107183

9.2CRITICAL

Key Information:

Vendor

Ggml-org

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107183?

The llama.cpp library, prior to version b11393, has a significant vulnerability in the common_chat_peg_mapper::map function, where a use-after-free and double free condition is present. This flaw enables unauthenticated remote attackers to exploit a dangling pointer in current_tool, leading to potential corruption of heap memory. By manipulating a chat_parser in a POST /completion request with a tool-id following a tool-close tag, an attacker can trigger a crash in the llama-server, paving the way for further exploits.

Affected Version(s)

llama.cpp b8227

llama.cpp b11393

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anas
.