Skip to content
OllamaGHSA-x8qc-fggm-mpqg

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

High9.1CVE-2026-7482 · Published May 4, 2026 · updated Sep 10, 2026

Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quantization in fs/ggml/gguf.go and server/quantization.go (WriteTo()), the server reads past the allocated heap buffer. The leaked memory contents may include environment variables, API keys, system prompts, and concurrent users' conversation data, and can be exfiltrated by uploading the resulting model artifact through the /api/push endpoint to an attacker-controlled registry. The /api/create and /api/push endpoints have no authentication in the upstream distribution. Default deployments bind to 127.0.0.1, but the documented OLLAMA_HOST=0.0.0.0 configuration is widely used in practice (large public-internet exposure observed).

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/ollama/ollama
Go
< 0.17.10.17.1
Details and references

More Ollama advisories

All Ollama
Advisory
Ollama is Vulnerable to Path Traversal
Low5.6Apr 26
Ollama Platform has missing authentication enabling attackers to perform model management operations
CriticalDec 18, 2025
Ollama allows deletion of arbitrary files
Medium6.6Aug 7, 2025
Ollama vulnerable to Cross-Domain Token Exposure
Medium6.9Jul 22, 2025
Ollama Server Vulnerable to Denial of Service (DoS) Attack
High7.5May 16, 2025
Ollama Divide By Zero vulnerability
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.