


Perceptive Security
SOC/SIEM Consultancy

Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file …
Published:
3 mei 2026 om 22:00:00
Alert date:
4 mei 2026 om 14:01:22
Source:
nvd.nist.gov
Emerging Technologies, Data Breach & Exfiltration
Ollama before version 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts maliciously crafted GGUF files where declared tensor offset and size exceed file length. During quantization, the server reads past allocated heap buffer boundaries. Leaked memory may contain sensitive data including environment variables, API keys, system prompts, and user conversation data. Attackers can exfiltrate this data by uploading resulting model artifacts through the /api/push endpoint. Both endpoints lack authentication in upstream distribution. While default deployments bind to localhost, the OLLAMA_HOST=0.0.0.0 configuration is widely used, creating significant public internet exposure.
Technical details
Mitigation steps:
Affected products:
Ollama
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7482
https://github.com/ollama/ollama/commit/88d57d0483cca907e0b23a968c83627a20b21047
https://github.com/ollama/ollama/pull/14406
https://github.com/ollama/ollama/releases/tag/v0.17.1
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
