CVE-2026-42248Disclosure(microsoft / ollama)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch microsoft ollama systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unconditionally returns success so no digital signature or trust validation is performed before staging or executing update payloads, enabling attacker‑supplied executables to be accepted and later executed by the application. Critically, Ollama for Windows performs silent automatic updates, so the malicious payload may be installed automatically without user awareness. Maintainers of this project were notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Versions from 0.12.10 to 0.17.5 were tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

2.5/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-494

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ollama
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-11); latest day: 3
  • 12 total mentions across 5 days

Affected systems

Products
ollamawindows

1 version affected across 2 products

Deep dive

Activity timeline12 mentions / 5d
01234Mentions · 2026-04-29: 2Mentions · 2026-05-05: 1Mentions · 2026-05-10: 2Mentions · 2026-05-11: 4Mentions · 2026-05-12: 3PoC Mentioned / Linked · 2026-04-29: 1Patch / Workaround · 2026-05-10: 2Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 2Technical Details · 2026-04-29: 2Technical Details · 2026-05-05: 1Technical Details · 2026-05-10: 2Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 104-2905-0505-1005-1105-12
Signal classification3 categories
Disclosure
541.7%
Patch
541.7%
General
216.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-292
Disclosure2
2026-05-051
Disclosure1
2026-05-102
Patch2
2026-05-114
Disclosure2General1Patch1
2026-05-123
General1Patch2
Full discourse12 posts
  • David Ondrej@DavidOndrej1
    Patch

    > run Claude Code root-level on your computer > paste in the following prompt: Audit my MacBook for exposure to the Ollama vulnerabilities disclosed on May 10, 2026 (CVE-2026-7482 "Bleeding Llama" — heap out-of-bounds read in GGUF loader on `/api/create`, fixed in 0.17.1; and CVE-2026-42248 / CVE-2026-42249 — Windows-only updater flaws affecting 0.12.10–0.22.0, can be skipped since this is macOS but confirm no Windows VM/Parallels instance is running Ollama) and produce a single concise final report — do not fix anything, only diagnose. Specifically: (1) check if Ollama is installed and get its version with `ollama --version` and `which ollama`, then compare against 0.17.1 to determine if the GGUF flaw applies; (2) determine whether the Ollama server is currently running and on what interface — run `lsof -nP -iTCP:11434 -sTCP:LISTEN` and `ps aux | grep -i ollama` to see if it's bound to `127.0.0.1` (safe, loopback only) or `0.0.0.0`/`*` (listening on all interfaces, network-reachable); (3) check the launch environment for `OLLAMA_HOST` — inspect `launchctl getenv OLLAMA_HOST`, `~/.zshrc`, `~/.zprofile`, `~/.bash_profile`, `~/.bashrc`, and any LaunchAgents/LaunchDaemons under `~/Library/LaunchAgents` and `/Library/LaunchAgents` for persistent `OLLAMA_HOST=0.0.0.0` settings; (4) determine the local network exposure layer — get the LAN IP with `ifconfig | grep "inet "`, check the macOS application firewall state with `/usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate` and whether Ollama is allowed/blocked, and note that even if bound to `0.0.0.0` the box is only LAN-reachable unless the upstream router forwards port 11434 (which the agent cannot verify from inside the host — flag this as a manual check); (5) check for any reverse proxy, Tailscale, ngrok, Cloudflare Tunnel, or similar tunneling tool that could expose 11434 publicly — run `ps aux | grep -E "ngrok|cloudflared|tailscaled|frp"` and `ls ~/Library/LaunchAgents`; (6) confirm no Windows Ollama instance is running in a Parallels/VMware/UTM VM by listing running VMs if any virtualization software is installed. Then output one short final report with: Ollama version + vulnerable yes/no, listening interface (loopback vs all), `OLLAMA_HOST` env state, LAN IP, tunneling tools detected, and a one-line verdict — "likely affected", "only-if-router-forwards-11434", or "not affected" — plus the single most important action to take. Do not modify any files, do not stop or start Ollama, do not change firewall rules.

    Post summary

    The post outlines audit steps for Ollama against CVE‑2026‑7482 and CVE‑2026‑42248/42249, noting the 0.17.1 patch as a mitigation and providing technical details to confirm version and exposure without deploying fixes.

    57013523432.5K
    63.7K followersView on X
  • striga@striga_ai
    General

    We reported CVE-2026-42248 and CVE-2026-42249 to @ollama on January 27. It is still unpatched. Read write-up on our findings here -> https://www.striga.ai/research/ollama-windows-auto-update-rce

    Post summary

    The note confirms that CVE-2026-42248 and CVE-2026-42249 are reported for Ollama, remain unpatched, and a write‑up is available for more information.

    15039255.8K
    536 followersView on X
  • striga@striga_ai
    Disclosure

    Persistent RCE in @ollama's Windows auto-updater. An HTTP header decides where the downloaded file lands on disk. The signature check that would catch this is one line: return nil. Windows runs the dropped binary every login. CVE-2026-42248 + CVE-2026-42249. Affected: 0.12.10 - 0.22.0. Still unpatched after the 90-day disclosure window. Thanks to @CERT_Polska for picking up coordination with the vendor unresponsive. https://striga.ai/research/ollama-windows-auto-update-rce

    Post summary

    CVE‑2026‑42248 and CVE‑2026‑42249 expose a persistent remote code execution flaw in Ollama’s Windows auto‑updater. Attackers can manipulate HTTP headers to place malicious binaries that execute on every user login, with no patch or mitigation currently available.

    01131727
    537 followersView on X
  • hackerman70000@hackerman_70000
    Disclosure

    @Dinosn Regarding Ollama, here is our article in which we explain our findings covered in THN article (CVE-2026-42248, CVE-2026-42249). We reported those in Jan, 2026, and the newest release is still unpatched. https://www.striga.ai/research/ollama-windows-auto-update-rce

    Post summary

    Striga.ai announces two new CVEs (CVE-2026-42248 and CVE-2026-42249) affecting Ollama’s Windows auto‑update feature, noting that the latest release remains unpatched.

    010311.4K
    34 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42248 Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the… https://www.cve.org/CVERecord?id=CVE-2026-42248

    Post summary

    The snippet announces that Ollama for Windows does not verify the integrity of its update executables, indicating a potential critical vulnerability.

    00011115
    57.3K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-6973 2 - CVE-2026-41940 3 - CVE-2026-43284 4 - CVE-2026-33634 5 - CVE-2026-42248 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVE IDs without providing any technical, exploit, or patch-related information.

    00010176
    1.7K followersView on X
  • yuzuno_oobaka@yuzuno_oobaka
    Patch

    3🪟 で,Windows版には更新機構に関する深刻な脆弱性(CVE-2026-42248 / 42249)が未修正の儘残ってる! Windowsユーザは自動更新をオフに 公式サイトから手動で最新版をインストールすること! デフォルトのlocalhost運用に戻すだけでも大幅にリスクを下げられる 環境見直していこー 🔗なんかは元🧵に

    Post summary

    The post warns that CVE‑2026‑42248/42249 remain unpatched on Windows and urges users to disable auto‑updates and install updates manually as a workaround.

    0000073
    25 followersView on X
  • yuzuno_oobaka@yuzuno_oobaka
    Patch

    3🪟 - 認証不要,攻撃コストが極めて低い - 0.17.1以降で修正済み Windows版の別脆弱性 CVE-2026-42248 / 42249(更新機構の問題)現在も未修正! Windows環境では自動更新を無効化,公式GitHubから手動更新 組織サーバ運用向けベストプラクティス - 基本:OLLAMA_HOST=127.0.0.1 の儘運用(外部公開極避け

    Post summary

    The post highlights the unpatched Windows CVEs CVE‑2026‑42248/42249 affecting the update mechanism, notes that the issue remains unsolved, and advises disabling auto‑updates and manually applying updates from GitHub.

    0000072
    25 followersView on X
  • AI Security Gateway@AISGateway
    Patch

    CVE-2026-7482 "Bleeding Llama" — CVSS 9.1, unauthenticated remote attack, 300,000+ exposed Ollama servers. This one has a data-specific impact that deserves attention beyond the patch advisory. The exploit chain is three steps: upload a malformed GGUF via HTTP POST, trigger the read through the /api/create endpoint, exfiltrate the heap contents via /api/push. No authentication required." The vulnerability sits in Ollama's GGUF model loader. A crafted file with inflated tensor offset values causes the server to read beyond allocated heap boundaries — and what's in that heap is the problem. Separate Windows flaws compound this. CVE-2026-42248 and CVE-2026-42249 (both CVSS 7.7, currently unpatched) combine missing update binary signature verification with a path traversal that allows arbitrary executable placement in the Startup folder — persistent code execution at user privilege on every login. Confirmed leakable data includes environment variables, API keys, system prompts, concurrent users' conversation data, and proprietary code. The AI-specific risk: teams running Ollama in self-hosted or hybrid setups are often doing so specifically because they want to keep data on-premises. This vulnerability puts API keys, system prompts, and live conversation data in scope for anyone who can reach the endpoint. Immediate actions: patch to Ollama 0.17.1+, restrict network access to the instance, deploy an authentication proxy in front of the endpoint, and disable auto-updates on Windows until the signature verification flaw is patched. The deeper question: if your local LLM deployment leaks heap memory containing API keys and user conversation data, how much of your governance posture was actually on-premises? → Full CVE breakdown: http://thehackernews.com/2026/05/ollama-out-of-bounds-read-vulnerability.html → Proxy-layer protection docs: http://aisecuritygateway.ai/docs #LLMSecurity #AISecurity #AIGovernance #DataPrivacy #CyberSecurity

    Post summary

    The post outlines an out-of-bounds read vulnerability in Ollama’s GGUF loader, details the data leak impact, and emphasizes patching and network hardening as necessary mitigations.

    0000054
    39 followersView on X
  • tpx Security ⠠⠵@tpx_Security
    Disclosure

    "Bleeding Llama" (CVE-2026-7482) es una falla crítica en el framework Ollama que permite a atacantes remotos extraer de la memoria del servidor claves API, prompts y conversaciones de usuarios mediante la carga de archivos GGUF maliciosos. Además, dos vulnerabilidades aún sin parchear en su versión para Windows (CVE-2026-42248 y CVE-2026-42249) habilitan la ejecución silenciosa y persistente de código abusando del sistema de actualizaciones.

    Post summary

    The post discloses two critical Ollama vulnerabilities, detailing how malicious files can retrieve sensitive data and how Windows can be exploited for silent, persistent code execution.

    0000091
    3.8K followersView on X
  • Cel Quintero 𝕏@Cel_Metal_
    Patch

    ⚠️ Using @ollama on Windows? Check your version. CVE-2026-42248 + CVE-2026-42249 (CVSS 7.7 each) Affected: 0.12.10 to 0.22.0 Patch status: UNPATCHED after 90 days of disclosure !! The patch was due yesterday, @ollama Cc. @StrigaAI @CERT_Polska

    Post summary

    The tweet alerts users that CVE-2026-42248 and CVE-2026-42249 affect ollama versions 0.12.10‑0.22.0, remain unpatched after 90 days, and urges the vendor to release the overdue patch.

    0000038
    1.8K followersView on X
  • Shah Sheikh@shah_sheikh
    Disclosure

    Unpatched flaws turn Ollama’s auto-updater into a persistent RCE vector, researchers say: Researchers at Striga have disclosed two vulnerabilities (CVE-2026-42248, CVE-2026-42249) in Ollama’s Windows auto-updater that, when chained together, may allow an… https://www.helpnetsecurity.com/2026/05/05/ollama-windows-vulnerabilities-cve-2026-42248-cve-2026-42249/?utm_source=dlvr.it&utm_medium=twitter https://t.co/uHil0gL95B

    Post summary

    Researchers have disclosed two chained CVEs in Ollama’s Windows auto-updater that enable persistent RCE; no patches, PoC or exploitation reports are included.

    0000059
    2.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows---
Appollamaollama---

Explore more