A high-severity vulnerability tracked as CVE-2026-39909 affects ggml-org llama.cpp versions before b8585, exposing the project's RPC server to unauthenticated remote compromise. The flaw is a use-after-free bug in the GRAPH_RECOMPUTE handler, where stored computation graphs can be re-executed after their referenced buffers have already been freed, leaving dangling pointers in memory.
Security advisories say an attacker can free those buffers, reclaim the released memory with attacker-controlled content, and then trigger graph recomputation to gain arbitrary read and write access, ultimately leading to remote code execution. The issue is classified as CWE-416 and carries a CVSS v3.1 vector of AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; published references point to a fixing commit, a GitHub pull request, a release tag, and a VulnCheck advisory documenting the bug.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
VulnCheck published an advisory describing a use-after-free flaw in llama.cpp before version b8585 in the RPC server's GRAPH_RECOMPUTE handler. The advisory said unauthenticated remote attackers could achieve arbitrary read/write access and potentially remote code execution without user interaction.
The CVE record states that disclosure@vulncheck.com received the new CVE on Aug. 21, 2026. The issue was identified as a use-after-free vulnerability in llama.cpp's RPC GRAPH_RECOMPUTE handler affecting versions before b8585.
A GitHub pull request titled "Conversation fix: Branching logic + small refactor" was merged into ggml-org/llama.cpp master with merge commit 389c7d4. The CVE record later referenced this commit and pull request as related to CVE-2026-39909, though the pull request content itself did not describe the vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.