VYPR
High severity7.5OSV Advisory· Published Jun 26, 2026· Updated Jun 29, 2026

CVE-2026-5757

CVE-2026-5757

Description

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

Affected products

3
  • Ollama/OllamaOSV3 versions
    v0.13.5-rc1, v0.13.5, v0.13.5-rc0, …+ 2 more
    • (no CPE)range: v0.13.5-rc1, v0.13.5, v0.13.5-rc0, …
    • cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*range: <=0.13.5
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.