Heap Memory Corruption in llama.cpp via CVE-2026-107183
An unauthenticated remote attacker can trigger a use-after-free or double-free condition in llama.cpp version b11393 or earlier by sending a malformed POST /completion request to achieve memory corruption.
CVE search metadata
CVE search record: CVE-2026-107183. Severity: high. CVSS: 8.1. KEV: no. Product: llama.cpp (< b11393). Brief: Heap Memory Corruption in llama.cpp via CVE-2026-107183. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-107183/
CVE-2026-107183 identifies a critical memory safety vulnerability within llama.cpp prior to build b11393. The flaw exists in the common_chat_peg_mapper::map function, which handles the parsing of chat interactions. An unauthenticated remote attacker can exploit this vulnerability by submitting a specifically crafted POST request to the /completion endpoint of the llama-server component. By inserting a tool-id tag immediately following a tool-close tag, an attacker triggers an invalid memory state involving a dangling current_tool pointer. This condition results in either a double-free or use-after-free error. Successful exploitation allows for the corruption of heap memory, which can lead to application crashes, denial of service, or the creation of a heap write primitive that may enable remote code execution.
Impact
The vulnerability affects the llama-server component, which is frequently deployed in local and containerized environments to serve large language models. Successful exploitation permits unauthenticated attackers to cause service instability and potential remote code execution, compromising the host system or container environment.
Recommendation
- Upgrade all instances of llama.cpp to build b11393 or later immediately to address the underlying memory management defect in common_chat_peg_mapper::map.
- Implement network access controls to restrict access to the /completion endpoint of llama-server, ensuring that only trusted internal services can reach the API.
- Deploy WAF or reverse-proxy rules to inspect incoming POST requests to /completion, specifically flagging payloads that contain consecutive tool-id tags following tool-close tags or irregular chat syntax.
Immediate actions
Upgrade llama.cpp to build b11393 or later
Mitigations
Restrict access to /completion endpoint
CVE-2026-107183
Detection coverage 1
Detect CVE-2026-107183 Exploitation - Suspicious POST to /completion
highDetects potential exploitation attempts of CVE-2026-107183 by identifying malformed chat parsing patterns in /completion API requests
Detection queries are available on the platform. Get full rules →