CVE-2026-7482
CVSS 9.1 CRITICAL: ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. EPSS 0.7% (52º percentile).
Vulnerabilità ed exploit
Heap out-of-bounds in Ollama GGUF loader (CVE-2026-7482) allows unauthenticated remote reads of heap memory, exposing prompts, env vars and secrets across ~300k deployments. CVEs: CVE-2026-7482.
3 fonti · 10 mag
CVSS 9.1 CRITICAL: ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. EPSS 0.7% (52º percentile).
The Hacker News
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
Critical out-of-bounds read in Ollama before 0.17.1 leaks process memory including API keys from over 300000 servers via crafted GGUF files.
originaleCSO Online
Ollama vulnerability highlights danger of AI frameworks with unrestricted access
Dubbed Bleeding Llama, the flaw gives attackers direct access to sensitive data stored in the most popular framework for running AI models on local hardware.
originaleSecurityWeek
Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft
Dubbed Bleeding Llama, the heap out-of-bounds read issue can be exploited remotely, without authentication.
originalePart of the PlainSec briefing for 2026-05-06
Every edition of this story: Ollama security issue includes CVE-2026-7482