THREAT OPS › Threat News › [NVD] CVE-2026-43631 (HIGH 8.1) — llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the vulnerabil
[NVD] CVE-2026-43631 (HIGH 8.1) — llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the vulnerabil
CVE-2026-43631 CVSS: 8.1 HIGH Published: 2026-08-06T22:17:06.200
llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the vulnerability by sending requests to affected endpoints while th
Indicators of compromise
- CVE-2026-43631cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-43631