Ollama GGUF model loader heap out-of-bounds read security flaw (CVE-2026-7482)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-7482 in Ollama is a critical GGUF model loader out-of-bounds read that can let a remote, unauthenticated attacker leak entire process memory from exposed servers. The flaw affects versions before 0.17.1 and is reachable through /api/create, making internet-facing deployments especially risky. Successful exploitation can expose API keys, system prompts, and other heap-resident data, which may then be exfiltrated through /api/push.
Related Happenings
ChromaDB Python API exposure mitigation (CVE-2026-45829)
Advisory/Mitigation
First: 20.05.2026 01:25
Last: 20.05.2026 01:25
Sources 1
About this happening:
**HiddenLayer** urged **ChromaDB** users to harden exposed deployments because **CVE-2026-45829** can still enable code execution on the **Python FastAPI** server. Until patch sta...
ChromaDB Python API exposure mitigation (CVE-2026-45829)
Advisory/MitigationAbout this happening: **HiddenLayer** urged **ChromaDB** users to harden exposed deployments because **CVE-2026-45829** can still enable code execution on the **Python FastAPI** server. Until patch sta...
OpenDCIM multi-flaw exploitation wave (CVE-2026-28515, CVE-2026-28516, CVE-2026-28517)
Exploitation Wave
First: 17.05.2026 14:57
Last: 17.05.2026 14:57
Sources 1
About this happening:
**openDCIM** is seeing an **active exploitation wave** tied to **CVE-2026-28515**, **CVE-2026-28516**, and **CVE-2026-28517**, with attackers targeting vulnerable installations an...
OpenDCIM multi-flaw exploitation wave (CVE-2026-28515, CVE-2026-28516, CVE-2026-28517)
Exploitation WaveAbout this happening: **openDCIM** is seeing an **active exploitation wave** tied to **CVE-2026-28515**, **CVE-2026-28516**, and **CVE-2026-28517**, with attackers targeting vulnerable installations an...
Timeline
-
10.05.2026 15:41 2 articles · 17d ago
Ollama CVE-2026-7482 disclosure
Initial DisclosureResearchers disclosed CVE-2026-7482 in Ollama, a critical heap out-of-bounds read in the GGUF model loader before 0.17.1 that can let a remote, unauthenticated attacker leak entire process memory through /api/create and /api/push. Cyera dubbed the flaw Bleeding Llama, and the reported exposure includes API keys, system prompts, concurrent users' conversation data, and other heap-resident information on exposed servers.
Show sources
- Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak — thehackernews.com — 10.05.2026 15:41
- Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak — thehackernews.com — 10.05.2026 15:41