CVE-2026-7482
CRITICALOllama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers
Title source: cnaExploitation Summary
EIP tracks 4 public exploits for CVE-2026-7482. PoCs published by adminlove520, kaleth4, szybnev.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-7482, an unauthenticated Out-of-Bounds (OOB) Read vulnerability in Ollama's GGUF model loader. The exploit crafts a malicious GGUF file, uploads it to the target, triggers memory corruption via quantization, and exfiltrates leaked heap memory to an attacker-controlled registry.
Description
Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quantization in fs/ggml/gguf.go and server/quantization.go (WriteTo()), the server reads past the allocated heap buffer. The leaked memory contents may include environment variables, API keys, system prompts, and concurrent users' conversation data, and can be exfiltrated by uploading the resulting model artifact through the /api/push endpoint to an attacker-controlled registry. The /api/create and /api/push endpoints have no authentication in the upstream distribution. Default deployments bind to 127.0.0.1, but the documented OLLAMA_HOST=0.0.0.0 configuration is widely used in practice (large public-internet exposure observed).
Exploits (4)
This repository contains a functional exploit for CVE-2026-7482, an unauthenticated Out-of-Bounds (OOB) Read vulnerability in Ollama's GGUF model loader. The exploit crafts a malicious GGUF file, uploads it to the target, triggers memory corruption via quantization, and exfiltrates leaked heap memory to an attacker-controlled registry.
This repository provides a detailed technical analysis of CVE-2026-7482, a heap buffer over-read vulnerability in Ollama's GGUF loader, including root cause analysis, exploitation mechanics, and mitigation strategies.
This repository contains a functional exploit PoC for CVE-2026-7482, demonstrating a heap out-of-bounds read in Ollama's GGUF model loader. The script creates malicious GGUF files, triggers quantization via the Ollama API, and compares outputs to confirm OOB-influenced artifacts.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H