← Back

CVE-2026-5757

nvd nist
Published: Jun 26, 2026Modified: Jun 29, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

Affected (1)

Products: Ollama: Ollama
1 product
Ollama
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.13.5

References (3)

Source: cret@cert.org
Third Party AdvisoryVDB Entry
Source: cret@cert.org
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.