CVE-2026-5757

HIGH

Ollama Model Quantization Engine - Unauthenticated Heap Memory Disclosure

Title source: manual
STIX 2.1

Description

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

References (3)

Core 3
Core References
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/518910

Scores

CVSS v3 7.5
EPSS 0.0055
EPSS Percentile 43.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (2)
ollama/ollama < 0.13.5
Ollama AI/Ollama v0.13.5
Published Jun 26, 2026
Tracked Since Jun 26, 2026