Skip to content
Threat Feed
high advisory

Heap Memory Corruption in llama.cpp via CVE-2026-107183

An unauthenticated remote attacker can trigger a use-after-free or double-free condition in llama.cpp version b11393 or earlier by sending a malformed POST /completion request to achieve memory corruption.

CVE search metadata

CVE search record: CVE-2026-107183. Severity: high. CVSS: 8.1. KEV: no. Product: llama.cpp (< b11393). Brief: Heap Memory Corruption in llama.cpp via CVE-2026-107183. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-107183/

CVE-2026-107183 identifies a critical memory safety vulnerability within llama.cpp prior to build b11393. The flaw exists in the common_chat_peg_mapper::map function, which handles the parsing of chat interactions. An unauthenticated remote attacker can exploit this vulnerability by submitting a specifically crafted POST request to the /completion endpoint of the llama-server component. By inserting a tool-id tag immediately following a tool-close tag, an attacker triggers an invalid memory state involving a dangling current_tool pointer. This condition results in either a double-free or use-after-free error. Successful exploitation allows for the corruption of heap memory, which can lead to application crashes, denial of service, or the creation of a heap write primitive that may enable remote code execution.

Impact

The vulnerability affects the llama-server component, which is frequently deployed in local and containerized environments to serve large language models. Successful exploitation permits unauthenticated attackers to cause service instability and potential remote code execution, compromising the host system or container environment.

Recommendation

  1. Upgrade all instances of llama.cpp to build b11393 or later immediately to address the underlying memory management defect in common_chat_peg_mapper::map.
  2. Implement network access controls to restrict access to the /completion endpoint of llama-server, ensuring that only trusted internal services can reach the API.
  3. Deploy WAF or reverse-proxy rules to inspect incoming POST requests to /completion, specifically flagging payloads that contain consecutive tool-id tags following tool-close tags or irregular chat syntax.

Immediate actions

Upgrade llama.cpp to build b11393 or later

IT Operations 24h

Mitigations

Restrict access to /completion endpoint

immediate IT Operations

CVE-2026-107183

Detection coverage 1

Detect CVE-2026-107183 Exploitation - Suspicious POST to /completion

high

Detects potential exploitation attempts of CVE-2026-107183 by identifying malformed chat parsing patterns in /completion API requests

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →