CVE-2026-7482

CRITICAL

Ollama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2026-7482. PoCs published by adminlove520, kaleth4, szybnev.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-7482, an unauthenticated Out-of-Bounds (OOB) Read vulnerability in Ollama's GGUF model loader. The exploit crafts a malicious GGUF file, uploads it to the target, triggers memory corruption via quantization, and exfiltrates leaked heap memory to an attacker-controlled registry.

Description

Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quantization in fs/ggml/gguf.go and server/quantization.go (WriteTo()), the server reads past the allocated heap buffer. The leaked memory contents may include environment variables, API keys, system prompts, and concurrent users' conversation data, and can be exfiltrated by uploading the resulting model artifact through the /api/push endpoint to an attacker-controlled registry. The /api/create and /api/push endpoints have no authentication in the upstream distribution. Default deployments bind to 127.0.0.1, but the documented OLLAMA_HOST=0.0.0.0 configuration is widely used in practice (large public-internet exposure observed).

Exploits (4)

github WORKING POC 4 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2026/CVE-2026-7482

This repository contains a functional exploit for CVE-2026-7482, an unauthenticated Out-of-Bounds (OOB) Read vulnerability in Ollama's GGUF model loader. The exploit crafts a malicious GGUF file, uploads it to the target, triggers memory corruption via quantization, and exfiltrates leaked heap memory to an attacker-controlled registry.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Ollama (versions prior to 0.17.1)
No auth needed
Prerequisites: Python 3 · requests library · numpy library · gguf library · publicly accessible HTTP listener (e.g., Ngrok)
devstral-2 · analyzed May 26, 2026 Full analysis →
nomisec WRITEUP
by kaleth4 · poc
https://github.com/kaleth4/CVE-2026-7482

This repository provides a detailed technical analysis of CVE-2026-7482, a heap buffer over-read vulnerability in Ollama's GGUF loader, including root cause analysis, exploitation mechanics, and mitigation strategies.

Classification
Writeup 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Ollama < 0.17.1
No auth needed
Prerequisites: Access to Ollama's `/api/create` or `/api/push` endpoints · Maliciously crafted GGUF file
devstral-2 · analyzed May 11, 2026 Full analysis →
nomisec WORKING POC
by szybnev · poc
https://github.com/szybnev/CVE-2026-7482

This repository contains a functional exploit PoC for CVE-2026-7482, demonstrating a heap out-of-bounds read in Ollama's GGUF model loader. The script creates malicious GGUF files, triggers quantization via the Ollama API, and compares outputs to confirm OOB-influenced artifacts.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Ollama < 0.17.1
No auth needed
Prerequisites: Python 3 with requests · Docker access to vulnerable Ollama container · Ollama 0.17.0 exposed on local API port
devstral-2 · analyzed May 08, 2026 Full analysis →

References (3)

Core 3
Core References
Patch patch
ollama/ollama PR #14406 — ggml: ensure tensor size is valid (fix)
https://github.com/ollama/ollama/pull/14406
Release Notes release-notes
ollama v0.17.1 release notes
https://github.com/ollama/ollama/releases/tag/v0.17.1

Scores

CVSS v3 9.1
EPSS 0.0076
EPSS Percentile 50.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-125
Status published
Products (2)
ollama/ollama < 0.17.1 (2 CPE variants)
ollama/ollama 0 - 0.17.1Go
Published May 04, 2026
Tracked Since May 04, 2026