CVE-2026-107183 — llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote a…
Description
llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCritical severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
AT
None
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
High
Confidentiality (Vulnerable System)
VI
High
Integrity (Vulnerable System)
VA
High
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
- advisory[email protected]https://github.com/ggml-org/llama.cpp
- advisory[email protected]https://github.com/ggml-org/llama.cpp/blob/bed0a856606ee4a24a164066f73d2379447033f5/common/chat-peg-parser.cpp#L343-L355
- advisory[email protected]https://github.com/ggml-org/llama.cpp/blob/bed0a856606ee4a24a164066f73d2379447033f5/tools/server/server-schema.cpp#L321-L324
- advisory[email protected]https://github.com/ggml-org/llama.cpp/commit/dbe4c3ed42343f0a7ba0fd7e808ffeaca404d29f
- advisory[email protected]https://github.com/ggml-org/llama.cpp/pull/29942
- advisory[email protected]https://www.vulncheck.com/advisories/llama-cpp-before-b11393-use-after-free-via-common-chat-peg-mapper-chat-parser
Related threats
same CWE or vendorCVE-2026-14508 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a re…
CVE-2026-14508 · 9h ago
CVE-2026-105824 — ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, …
CVE-2026-105824 · 9h ago
CVE-2026-107209 — ImageMagick is free and open-source software used for editing and manipulating digital images.
CVE-2026-107209 · 1d ago
CVE-2026-107167 — A flaw was found in m17n-lib.
CVE-2026-107167 · 1d ago
CVE-2026-55330 — In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code.
CVE-2026-55330 · 2d ago
CVE-2026-106423 — Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafte…
CVE-2026-106423 · 2d ago