Use-After-Free Vulnerability in Llama-Server by Llama.cpp
CVE-2026-43632
9.2CRITICAL
What is CVE-2026-43632?
Llama-server versions from b7492 to b9060 are affected by a use-after-free vulnerability that compromises six key tokenization endpoints, including /tokenize and /rerank. This issue arises due to a race condition between the destruction of the vocabulary object and the processing of requests on HTTP worker threads, which can lead to application crashes or unauthorized code execution under specific configurations. It is crucial for users to address this vulnerability to maintain the integrity and security of their applications.
Affected Version(s)
llama.cpp b7492
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Vladimir Tokarev (@G1ND1L4) - Vulnerability Research Tech Lead, Cyera
Ofek Itach (@ofekitach) - Security Research Team Lead, Cyera
