Important
Current release: 2026 — published August 4, 2026.
Get the 2026 publication · Read the canonical source · Report a correction
This is the official source repository for the OWASP Top 10 for Large Language Model Applications, maintained as a core initiative of the OWASP GenAI Security Project.
The Top 10 is a community-developed awareness document for developers, architects, data scientists, security practitioners, and organizations building or operating applications that use large language models.
The 2026 release is complete. The publication combines community judgment with analysis of real-world incidents and updates the ordering, scope, examples, mitigations, and framework mappings across the list.
| Resource | Location |
|---|---|
| Official publication | Get the OWASP GenAI LLM Top 10 2026 |
| Canonical Markdown source | 2026/final/ |
| Release overview | 2026/README.md |
| Previous release | 2025/ |
- LLM01:2026 Prompt Injection
- LLM02:2026 Sensitive Information Disclosure
- LLM03:2026 Excessive Agency
- LLM04:2026 Supply Chain
- LLM05:2026 Data and Model Poisoning
- LLM06:2026 Unbounded Consumption
- LLM07:2026 Misinformation
- LLM08:2026 Hidden Context Exposure
- LLM09:2026 Vector and Embedding Weaknesses
- LLM10:2026 Improper Output Handling
2026/final/— canonical source for the published 2026 release2026/working/— historical working files and release-cycle tooling2025/— source for the previous releasedocumentation/style/— editorial and branding guidance- Project charter — mission, scope, governance, and operating principles
The 2026 sprint plan and 2026/working/CONTRIBUTING.md are retained as records of the completed release process. They are not the current contribution workflow.
Post-release corrections and improvements are welcome. Use the 2026 release errata form for specific errors, broken links, or source/publication mismatches. Use the release feedback form for broader feedback or proposals for a future cycle.
Important
All changes to this repository must be made through a pull request. Direct pushes to main are blocked by branch protection.
We have a working group channel on OWASP Slack: #team-genai-top-10-llm.
For the broader project contribution process, visit genai.owasp.org/contribute.
This project is licensed under the Creative Commons Attribution-ShareAlike 4.0 International License.
