CVE-2026-7482 - Vulnerability Analysis
CriticalCVSS: 9.1Last Updated: May 4, 2026
Ollama - Information Disclosure
Published: May 4, 2026Updated: May 4, 2026Remote Exploitable
Overview
Ollama < 0.17.1 contains a heap out-of-bounds read caused by improper validation of tensor offset and size in GGUF model loader, letting remote attackers leak sensitive memory data via /api/create and /api/push endpoints, exploit requires no authentication.
Severity & Score
Severity: Critical
CVSS Score: 9.1
Impact
Remote attackers can leak sensitive memory contents including environment variables, API keys, and user data, leading to information disclosure.
Mitigation
Update to version 0.17.1 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-7482
- Severity
- Critical
- CVSS Score
- 9.1
- Type
- out_of_bounds_rw
- Status
- new
CWE
- CWE-125
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H