Summary
CVE-2026-43632 is a use-after-free vulnerability in the llama.cpp llama-server HTTP server (ggml-org), affecting builds b7492 through b9060. Six tokenization endpoints access the server’s vocabulary object directly on HTTP worker threads, creating a time-of-check-to-time-of-use race that a remote, unauthenticated attacker can trigger. It is rated Critical (CVSS v4.0 9.2).
Technical details
- Root cause: The
/tokenize,/detokenize,/infill,/apply-template,/rerank, and/anthropic/count_tokensendpoints bypass the task queue and accessctx_server.vocabdirectly on HTTP worker threads (CWE-416 Use After Free, CWE-367 TOCTOU race condition). - Trigger conditions: A race in which the main thread destroys and frees
vocabafter the synchronization lock is released but before the handler finishes using it; exploitation is associated with the--sleep-idle-secondsoption being configured. - Attack vector: Network — the affected endpoints are reachable over the HTTP interface without authentication.
- Impact: Use-after-free with high impact to confidentiality, integrity, and availability.
Affected software
- llama.cpp (
llama-server, ggml-org) builds b7492 through b9060, inclusive.
Severity
- CVSS v3.1 base score: 8.1 (High) — vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. - CVSS v4.0 base score: 9.2 (Critical) — vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.
Mitigation and recommended actions
- Immediate: No official fixed build was published by the maintainers at time of disclosure. Apply the researcher-provided source patch to affected llama.cpp installations and rebuild.
- If no patch: The exploit condition is associated with
--sleep-idle-seconds; avoid enabling this option. Restrict network access tollama-serverso the HTTP endpoints are not exposed to untrusted networks, and place the server behind authenticated, access-controlled proxies.

