Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107183— llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser

Quick assessment

Affected
ggml-org llama.cpp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

llama.cpp 版本在 b11393 之前,在 函数中存在使用后释放(use-after-free)和重复释放(double free)漏洞。该漏洞允许未认证的远程攻击者通过悬空的 current_tool 指针破坏堆内存。攻击者可以在 POST /completion 请求中提交一个 chat_parser,在 tool-close 标签后发出 tool-id,从而导致 llama-server 崩溃,并构造出堆写入原语(heap write primitive)。

CVSS 8.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107183

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser
Source: CVE Program / CVE List V5
Vulnerability Description
llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
释放后使用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ggml-org llama.cpp b8227 ~ b11393 -

II. Public POCs for CVE-2026-107183

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107183

请登录查看更多情报信息。

Vendor Pages for CVE-2026-107183 (1)

Other References for CVE-2026-107183 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107183

No comments yet


Leave a comment