Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive. | |
| Title | llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser | |
| First Time appeared |
Ggml
Ggml llama.cpp |
|
| Weaknesses | CWE-416 | |
| CPEs | cpe:2.3:a:ggml:llama.cpp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ggml
Ggml llama.cpp |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-07T14:37:12.658Z
Reserved: 2026-10-07T13:04:03.727Z
Link: CVE-2026-107183
Updated: 2026-10-07T14:37:05.670Z
Status : Received
Published: 2026-10-07T14:17:09.003
Modified: 2026-10-07T15:17:19.913
Link: CVE-2026-107183
No data.
OpenCVE Enrichment
No data.
-
CWE-416
Use After Free