OWASP Top 10 for Large Language Model Applications
- Wilson, Steve
-
Lambros, Rock
- James, Rachel
- Guilherme, Emmanuel
-
Huang, Ken
- Smith, Andy
- Sotiropoulos, John
-
Amorelli, Stefano
-
Jeswani, Sumeet
- Roxberry, Mark
- Dakamarri, Anitha
- Mehta, Sahil
- Modalavalasa, Venkata Sai Kishore
- Leung, Alex
- Giarrusso, Vinnie
- Kumar, Sonu
- Dsouza, Savio
-
Chadha, Arshi
- Komenda, Rico
- Klondike, Gavin
Contributors
Hosting institution:
Description
OWASP Top 10 for LLM Applications 2026 is the latest community-driven guide to the most critical security risks facing applications powered by large language models. Developed by hundreds of AI security experts, this edition introduces updated rankings, expanded threat coverage, and new research grounded in thousands of real-world AI security incidents. The guide provides practical explanations, attack scenarios, and actionable mitigations for developers, architects, security teams, and CISOs, while mapping risks to leading industry frameworks including NIST, MITRE ATLAS, CWE, and the OWASP Top 10 for Agentic Applications, making it an essential resource for building and securing modern AI.
The 2026 list:
- LLM01:2026 Prompt Injection
- LLM02:2026 Sensitive Information Disclosure
- LLM03:2026 Excessive Agency
- LLM04:2026 Supply Chain
- LLM05:2026 Data and Model Poisoning
- LLM06:2026 Unbounded Consumption
- LLM07:2026 Misinformation
- LLM08:2026 Hidden Context Exposure
- LLM09:2026 Vector and Embedding Weaknesses
- LLM10:2026 Improper Output Handling
Published by the OWASP GenAI Security Project.
Official publication website: https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/
Project site: https://genai.owasp.org/llm-top-10/
Files
OWASP-GenAI-LLM-Top-10-2026-v1.0.pdf
Files
(4.6 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:7a4ef5d6d14471baf9829649d75bce3f
|
2.4 MB | Preview Download |
|
md5:9440bef3304f8119c220c13c3b92f3a3
|
2.2 MB | Preview Download |
Additional details
Related works
- Is supplement to
- Other: https://genai.owasp.org/llm-top-10/ (URL)
Software
- Repository URL
- https://github.com/GenAI-Security-Project/GenAI-LLM-Top10
- Development Status
- Active