CVE-2026-5757
HIGHOllama Model Quantization Engine - Unauthenticated Heap Memory Disclosure
Title source: manualDescription
Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.
References (3)
Core 3
Core References
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/518910
Scores
CVSS v3
7.5
EPSS
0.0055
EPSS Percentile
43.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-125
Status
published
Products (2)
ollama/ollama
< 0.13.5
Ollama AI/Ollama
v0.13.5
Published
Jun 26, 2026
Tracked Since
Jun 26, 2026