CVE-2026-43632 PUBLISHED

llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints

Assigner: VulnCheck
Reserved: 01.05.2026 Published: 06.08.2026 Updated: 06.08.2026

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task queue and access ctx_server.vocab directly on HTTP worker threads. Attackers can exploit a time-of-check-time-of-use race condition where the main thread destroys and frees vocab after the synchronization lock is released but before the handler finishes using it, causing a crash or potential code execution when --sleep-idle-seconds is configured.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor ggml-org
Product llama.cpp
Versions Default: affected
  • affected from b7492 to b9060 (incl.)

Credits

  • Vladimir Tokarev (@G1ND1L4) - Vulnerability Research Tech Lead, Cyera finder
  • Ofek Itach (@ofekitach) - Security Research Team Lead, Cyera finder

References

Problem Types

  • CWE-416 Use After Free CWE
  • CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition CWE