{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/llama.cpp--b11393/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:llama_cpp:llama_cpp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-107183"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["llama.cpp (\u003c b11393)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","webserver"],"_cs_type":"advisory","_cs_vendors":["llama.cpp"],"content_html":"\u003cp\u003eCVE-2026-107183 identifies a critical memory safety vulnerability within llama.cpp prior to build b11393. The flaw exists in the common_chat_peg_mapper::map function, which handles the parsing of chat interactions. An unauthenticated remote attacker can exploit this vulnerability by submitting a specifically crafted POST request to the /completion endpoint of the llama-server component. By inserting a tool-id tag immediately following a tool-close tag, an attacker triggers an invalid memory state involving a dangling current_tool pointer. This condition results in either a double-free or use-after-free error. Successful exploitation allows for the corruption of heap memory, which can lead to application crashes, denial of service, or the creation of a heap write primitive that may enable remote code execution.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects the llama-server component, which is frequently deployed in local and containerized environments to serve large language models. Successful exploitation permits unauthenticated attackers to cause service instability and potential remote code execution, compromising the host system or container environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of llama.cpp to build b11393 or later immediately to address the underlying memory management defect in common_chat_peg_mapper::map.\u003c/li\u003e\n\u003cli\u003eImplement network access controls to restrict access to the /completion endpoint of llama-server, ensuring that only trusted internal services can reach the API.\u003c/li\u003e\n\u003cli\u003eDeploy WAF or reverse-proxy rules to inspect incoming POST requests to /completion, specifically flagging payloads that contain consecutive tool-id tags following tool-close tags or irregular chat syntax.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-07T14:37:43Z","date_published":"2026-10-07T14:37:43Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-107183/","summary":"An unauthenticated remote attacker can trigger a use-after-free or double-free condition in llama.cpp version b11393 or earlier by sending a malformed POST /completion request to achieve memory corruption.","title":"Heap Memory Corruption in llama.cpp via CVE-2026-107183","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-107183/"}],"language":"en","title":"CraftedSignal Threat Feed - Llama.cpp (\u003c B11393)","version":"https://jsonfeed.org/version/1.1"}