LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-7482 - Vulnerability Analysis

CriticalCVSS: 9.1

Last Updated: May 4, 2026

Ollama - Information Disclosure

Published: May 4, 2026Updated: May 4, 2026Remote Exploitable

Overview

Ollama < 0.17.1 contains a heap out-of-bounds read caused by improper validation of tensor offset and size in GGUF model loader, letting remote attackers leak sensitive memory data via /api/create and /api/push endpoints, exploit requires no authentication.

Severity & Score

Severity: Critical
CVSS Score: 9.1

Impact

Remote attackers can leak sensitive memory contents including environment variables, API keys, and user data, leading to information disclosure.

Mitigation

Update to version 0.17.1 or later.

Details

CVE ID
CVE-2026-7482
Severity
Critical
CVSS Score
9.1
Type
out_of_bounds_rw
Status
new

CWE

  • CWE-125

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H