CVE-2026-107183: llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser
llama.cpp before b11393 contains a use-after-free and double free vulnerability in commonchatpegmapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling currenttool pointer. Attackers can submit a chatparser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments running llama.cpp before b11393 with llama-server reachable over the network are exposed if an attacker can send POST requests to the /completion endpoint. The attack does not require authentication or user interaction.
What request content is required to trigger the flaw?
An attacker must submit a chat_parser that emits a tool-id after a tool-close tag. This leaves a dangling current_tool pointer in common_chat_peg_mapper::map, leading to use-after-free and double-free behavior.
What is the likely impact of successful exploitation?
Successful exploitation can crash llama-server and corrupt heap memory. The reported behavior can also give an attacker the ability to shape a heap write primitive, with high confidentiality, integrity, and availability impact.
How can I determine whether an instance needs remediation?
Check whether the deployed llama.cpp version is earlier than b11393 and whether llama-server accepts POST /completion requests. Instances meeting both conditions should be treated as affected.