Critical Ollama Memory Leak Vulnerability Exposes 300,000 Servers Globally
ID: 09e04fee-910b-57ca-b838-8464fcaaa59b
STIX ID: report--09e04fee-910b-57ca-b838-8464fcaaa59b
Feed Name: cybersecurityNews.com
A critical vulnerability in Ollama (CVE-2026-7482, "Bleeding Llama") lets an attacker submit a malformed GGUF model to force out-of-bounds heap reads during tensor conversion, leaking memory contents (prompts, system instructions, environment variables, API keys) that can be preserved via float16→float32 conversion and exfiltrated by pushing the crafted model to a remote server; the issue affects versions prior to 0.17.1, has a CVSS score of 9.1, and organizations are advised to upgrade, remove public exposure, restrict access, rotate secrets, and assume possible compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
