CERT Polska disclosed two vulnerabilities in Ollama for Windows—CVE-2026-42248 and CVE-2026-42249—that affect tested versions 0.12.10 through 0.17.5 and expose the software’s update mechanism to malicious payloads. According to the advisory, the first flaw causes the Windows updater to accept downloaded executables without properly verifying their integrity or authenticity, while the second lets attacker-controlled HTTP response headers influence file path construction, enabling path traversal and arbitrary file writes. CERT Polska said an attacker able to tamper with update responses could combine the bugs to stage and run unauthorized code during Ollama’s silent automatic update process.
The chained attack could allow malicious executables to be written into sensitive locations such as the Windows Startup directory, resulting in automatic and persistent code execution without user awareness. CERT Polska credited Bartłomiej Dmitruk of striga.ai with the report and said maintainers were notified early, but no vendor details on the vulnerabilities or affected versions were provided. Separate reporting later listed the Ollama issues among a broader set of publicly validated CVEs attributed by Striga’s tracker, while noting that the AI-assisted discovery claims were self-reported rather than independently confirmed by upstream vendors.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
Apache HTTP Server fixed heap-underflow vulnerability CVE-2026-44631 in version 2.4.68 and credited DepthFirst and Bartlomiej Dmitruk of Striga for the report. The source does not specify the date the fix was released.
CERT Polska disclosed two vulnerabilities affecting Ollama for Windows and stated both CVEs were published on 2026-04-29. The flaws allow malicious update payload execution and, when chained, can enable persistent remote code execution via the Windows Startup directory.
CERT Polska said Ollama maintainers were notified early about two Windows update-mechanism vulnerabilities, later tracked as CVE-2026-42248 and CVE-2026-42249. The notice does not provide a specific date for when the report was sent.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
bugflation.com
Open sourcebugflation.com
Open sourcecert.pl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.