Junglewise Threat Intelligence

CVE-2026-5757: Ollama AI Ollama heap memory disclosure in quantization engine

CVE-2026-5757 · Severity: info · CVSS 0 · Published 2026-06-26

Technologies: Ollama. Vendors: Ollama.

Executive brief

Ollama is an open-source tool used to run large language models locally. A security flaw in its model processing engine allows an unauthorized person to upload a malicious file that tricks the server into revealing its internal memory. This could lead to the theft of sensitive data, such as private keys or user information, and potentially allow an attacker to gain deeper access to the system.

Technical details

An out-of-bounds heap read/write vulnerability exists in Ollama's model quantization engine due to a lack of bounds checking on tensor metadata. The engine trusts the element count provided in a user-supplied GGUF file header and uses Go's 'unsafe.Slice' to create memory slices based on this attacker-controlled value. This allows an attacker to read beyond the intended buffer into the application's heap. The leaked data is then written into a new model layer, which can be exfiltrated via Ollama's registry API. As of the advisory date, no patch is available, and users are advised to restrict access to the model upload interface.

Affected products

  • Ollama AI Ollama v0.13.5

Timeline

  • 2026-02-09: other: Vendor notified
  • 2026-04-22: disclosed: Initial public disclosure by CERT/CC
  • 2026-06-26: advisory: NVD publication date

References

Related threats