CVE 7.5 HIGH

There exists an unauthenticated remote information disclosure vulnerability in Ollama’s model quantization engine_CVE-2026-5757

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

Basic Information

ID CVE-2026-5757
Source certcc
Published Jun 26, 2026 at 15:15
Modified Jun 26, 2026 at 18:38

Affected Product

Vendor Ollama AI
Product Ollama
Version v0.13.5
Affected Versions Ollama AI Ollama v0.13.5

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.