CVE-2026-39909: llama.cpp Use-After-Free in RPC GRAPH_RECOMPUTE Handler

Published Aug 21, 2026
·
Updated

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPHRECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by storing a computation graph, freeing referenced buffers, and reclaiming freed memory with attacker-controlled content. Attackers can send RPC requests to trigger re-execution of stored graphs with dangling pointers, enabling full remote code execution without requiring authentication or user interaction.

Affected Software

1 affected component
llama.cpp<b8585

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade llama.cpp to a version that resolves this vulnerability.

    Fixed in b8585
  2. Compensating control

    If you cannot immediately upgrade llama.cpp to a version where the GRAPH_RECOMPUTE handler use-after-free is fixed, restrict network access to the llama.cpp RPC server so unauthenticated attackers cannot send RPC requests that trigger GRAPH_RECOMPUTE re-execution (e.g., allow only trusted IPs over the RPC port).

Event History

Aug 21, 2026
CVE Published
via MITRE·04:28 PM
Data Sourced
via MITRE·04:28 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments running an affected llama.cpp version with its RPC server reachable by an attacker are exposed. The vulnerable handler is part of the RPC server, so systems not offering that service are not described as affected by this attack path.

2

Does exploitation require credentials or user interaction?

No. The issue is exploitable by an unauthenticated remote attacker and requires no user interaction.

3

What capabilities does an attacker need to exploit the flaw?

An attacker needs to send RPC requests that store a computation graph, free buffers referenced by that graph, reclaim the freed memory with attacker-controlled content, and then trigger graph re-execution through GRAPH_RECOMPUTE. Successful exploitation can provide arbitrary read and write access and lead to remote code execution.

4

What version resolves the issue?

The vulnerability affects llama.cpp versions before b8585. Updating to b8585 or later addresses the affected version range described here.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203