logo

Ollama vulnerability CVE-2026-7482: Find impacted assets

ID: 4327be78-f333-5793-a851-c22972af7ef8

STIX ID: report--4327be78-f333-5793-a851-c22972af7ef8

Feed Name: runZero Blog

Threat Score
88/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Matthew Kienow

...
...

A critical vulnerability (CVE-2026-7482, "Bleeding Llama", CVSS 9.1) in Ollama's GGUF model loader permits unauthenticated remote attackers to craft GGUF files that cause heap out-of-bounds reads during quantization, leaking sensitive data (environment variables, API keys, system prompts, conversation data) which can be exfiltrated by pushing the resulting model to attacker-controlled registries; affected versions are Ollama prior to 0.17.1 and users are advised to upgrade to 0.17.1 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.