CERT/CC disclosed VU#518910 for an Ollama vulnerability that lets unauthenticated remote attackers leak sensitive data from server heap memory through the platform’s model upload feature. The issue, tracked as CVE-2026-5757, affects Ollama’s handling of specially crafted GGUF model files and was reported by researcher Jeremy Brown, who found that malformed uploads could trigger unsafe memory access and expose heap contents during model processing.
Reporting said the flaw stems from improper bounds checking in Go code and the creation of a new model layer that can exfiltrate leaked memory through Ollama’s registry API. With no vendor patch available at disclosure and the vendor reportedly unreachable, CERT/CC urged organizations to disable model uploads where possible, restrict Ollama access to trusted local networks, block untrusted external IP addresses, and accept uploads only from verified sources.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
A new vulnerability, CVE-2026-7482, was disclosed affecting Ollama versions before 0.17.1, where crafted GGUF tensor metadata can trigger a heap out-of-bounds read via the unauthenticated /api/create endpoint and leak server memory. The reference indicates the issue is fixed in version 0.17.1 and notes possible exfiltration through the unauthenticated /api/push endpoint.
At the time of disclosure, no vendor patch was available and the vendor was reportedly unreachable. CERT/CC advised defenders to disable model uploads where possible, restrict access to trusted local networks, block untrusted external IPs, and accept uploads only from verified sources.
Security researcher Jeremy Brown publicly disclosed CVE-2026-5757 on April 22, 2026, describing an unauthenticated remote memory leak via Ollama's model upload interface. The flaw involves specially crafted GGUF model files that can expose sensitive heap memory data.
CERT/CC published vulnerability note VU#518910 describing a remote memory leak issue in Ollama related to GGUF quantization/model handling. The advisory established the issue as a tracked vulnerability by February 9, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcerunzero.com
Open sourcecvefeed.io
Open sourcecybersecuritynews.com
Open sourcekb.cert.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.