CVE-2026-42249Disclosure(microsoft / ollama)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft ollama systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the application constructs local file paths using values derived from HTTP headers without validation. These values are passed directly to filepath.Join, allowing path traversal sequences (../) to be resolved and enabling files to be written outside the intended update staging directory. An attacker who can influence update responses can exploit this flaw to write arbitrary executables to attacker‑chosen locations accessible to the current user, including the Windows Startup directory. This allows execution of arbitrary executables. Critically, when chained with CVE‑2026‑42248 (Missing Signature Verification for Updates), an attacker can deliver malicious payloads that are written to sensitive locations and executed automatically. Because Ollama for Windows performs silent automatic updates and executes staged binaries without user interaction, this results in automatic and persistent code execution without user awareness. Maintainers of this project were notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Versions from 0.12.10 to 0.17.5 were tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

4.5/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-22CWE-494

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ollama
  • windows

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • Peaked 2d ago at 4 mentions (2026-05-11); latest day: 1
  • 11 total mentions across 6 days

Affected systems

Products
ollamawindows

1 version affected across 2 products

Deep dive

Activity timeline11 mentions / 6d
01234Mentions · 2026-04-29: 2Mentions · 2026-05-05: 1Mentions · 2026-05-10: 2Mentions · 2026-05-11: 4Mentions · 2026-05-12: 1Mentions · 2026-06-29: 1PoC Mentioned / Linked · 2026-04-29: 1PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-11: 1Patch / Workaround · 2026-05-10: 2Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-04-29: 2Technical Details · 2026-05-05: 1Technical Details · 2026-05-10: 2Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 1Technical Details · 2026-06-29: 104-2905-0505-1005-1105-1206-29
Signal classification3 categories
Disclosure
763.6%
Patch
327.3%
Exploit
19.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-292
Disclosure2
2026-05-051
Disclosure1
2026-05-102
Patch2
2026-05-114
Disclosure3Exploit1
2026-05-121
Patch1
2026-06-291
Disclosure1
Full discourse11 posts
  • David Ondrej@DavidOndrej1
    Patch

    > run Claude Code root-level on your computer > paste in the following prompt: Audit my MacBook for exposure to the Ollama vulnerabilities disclosed on May 10, 2026 (CVE-2026-7482 "Bleeding Llama" — heap out-of-bounds read in GGUF loader on `/api/create`, fixed in 0.17.1; and CVE-2026-42248 / CVE-2026-42249 — Windows-only updater flaws affecting 0.12.10–0.22.0, can be skipped since this is macOS but confirm no Windows VM/Parallels instance is running Ollama) and produce a single concise final report — do not fix anything, only diagnose. Specifically: (1) check if Ollama is installed and get its version with `ollama --version` and `which ollama`, then compare against 0.17.1 to determine if the GGUF flaw applies; (2) determine whether the Ollama server is currently running and on what interface — run `lsof -nP -iTCP:11434 -sTCP:LISTEN` and `ps aux | grep -i ollama` to see if it's bound to `127.0.0.1` (safe, loopback only) or `0.0.0.0`/`*` (listening on all interfaces, network-reachable); (3) check the launch environment for `OLLAMA_HOST` — inspect `launchctl getenv OLLAMA_HOST`, `~/.zshrc`, `~/.zprofile`, `~/.bash_profile`, `~/.bashrc`, and any LaunchAgents/LaunchDaemons under `~/Library/LaunchAgents` and `/Library/LaunchAgents` for persistent `OLLAMA_HOST=0.0.0.0` settings; (4) determine the local network exposure layer — get the LAN IP with `ifconfig | grep "inet "`, check the macOS application firewall state with `/usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate` and whether Ollama is allowed/blocked, and note that even if bound to `0.0.0.0` the box is only LAN-reachable unless the upstream router forwards port 11434 (which the agent cannot verify from inside the host — flag this as a manual check); (5) check for any reverse proxy, Tailscale, ngrok, Cloudflare Tunnel, or similar tunneling tool that could expose 11434 publicly — run `ps aux | grep -E "ngrok|cloudflared|tailscaled|frp"` and `ls ~/Library/LaunchAgents`; (6) confirm no Windows Ollama instance is running in a Parallels/VMware/UTM VM by listing running VMs if any virtualization software is installed. Then output one short final report with: Ollama version + vulnerable yes/no, listening interface (loopback vs all), `OLLAMA_HOST` env state, LAN IP, tunneling tools detected, and a one-line verdict — "likely affected", "only-if-router-forwards-11434", or "not affected" — plus the single most important action to take. Do not modify any files, do not stop or start Ollama, do not change firewall rules.

    Post summary

    The message outlines steps to verify whether an Ollama installation is affected by CVE-2026-7482 and other updates, referencing the patch version 0.17.1 as the mitigation.

    57013523432.5K
    63.7K followersView on X
  • striga@striga_ai
    Disclosure

    We reported CVE-2026-42248 and CVE-2026-42249 to @ollama on January 27. It is still unpatched. Read write-up on our findings here -> https://www.striga.ai/research/ollama-windows-auto-update-rce

    Post summary

    Researchers reported two unpatched CVEs to the vendor and shared a write‑up detailing their findings.

    15039255.8K
    536 followersView on X
  • striga@striga_ai
    Disclosure

    Persistent RCE in @ollama's Windows auto-updater. An HTTP header decides where the downloaded file lands on disk. The signature check that would catch this is one line: return nil. Windows runs the dropped binary every login. CVE-2026-42248 + CVE-2026-42249. Affected: 0.12.10 - 0.22.0. Still unpatched after the 90-day disclosure window. Thanks to @CERT_Polska for picking up coordination with the vendor unresponsive. https://striga.ai/research/ollama-windows-auto-update-rce

    Post summary

    A new persistent RCE affecting Ollama's Windows auto‑updater was disclosed, impacting versions 0.12.10‑0.22.0, with technical details but no patch or exploit code yet.

    01131727
    537 followersView on X
  • hackerman70000@hackerman_70000
    Disclosure

    @Dinosn Regarding Ollama, here is our article in which we explain our findings covered in THN article (CVE-2026-42248, CVE-2026-42249). We reported those in Jan, 2026, and the newest release is still unpatched. https://www.striga.ai/research/ollama-windows-auto-update-rce

    Post summary

    Striga AI shares an article detailing findings on two unpatched CVEs in Ollama, noting the vulnerabilities remain unaddressed in the latest release.

    010311.4K
    34 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42249 Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When … https://www.cve.org/CVERecord?id=CVE-2026-42249

    Post summary

    A new RCE vulnerability (CVE‑2026‑42249) in Ollama for Windows has been disclosed, attributing the flaw to improper handling of attacker‑controlled HTTP response headers in its update mechanism.

    00010125
    57.3K followersView on X
  • IntegSec@integ_sec
    Disclosure

    🚨 Cyber Spotlight: CVE-2026-42249 – Ollama Update Path Traversal Bug A newly identified vulnerability in the Ollama update process could allow path traversal exploitation, potentially enabling attackers to access or manipulate sensitive files outside intended directories. In this episode, we break down: 🔍 What the vulnerability is ⚠️ How it could impact your business 🛡️ What steps you should take to reduce risk 📌 How to respond effectively and stay protected Understanding vulnerabilities like this is critical for maintaining a strong security posture in today’s threat landscape. 👉 Follow us for more cybersecurity insights. https://hubs.li/Q04mFSb50 🌐 Visit our website for CVE blogs, threat updates, and security resources #CyberSecurity #InfoSec #CVE #Vulnerability #Ollama #PathTraversal #ApplicationSecurity #CyberAwareness #ThreatIntel #SecurityUpdate #IncidentResponse #DevSecOps #CloudSecurity #SoftwareSecurity #CyberDefense #PatchManagement #HackingPrevention #SecurityFirst #TechAwareness #CyberSpotlight

    Post summary

    The post announces CVE-2026-42249, a path traversal flaw in Ollama's update process, and offers high‑level mitigation guidance without detailing PoC, exploits, or patches.

    0000051
    31 followersView on X
  • IntegSec@integ_sec
    Patch

    CVE-2026-42249: Ollama Update Path Traversal Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04gcL110

    Post summary

    The text highlights a path traversal vulnerability in Ollama update mechanisms and implies the article provides remediation steps.

    0000032
    30 followersView on X
  • AI Security Gateway@AISGateway
    Exploit

    CVE-2026-7482 "Bleeding Llama" — CVSS 9.1, unauthenticated remote attack, 300,000+ exposed Ollama servers. This one has a data-specific impact that deserves attention beyond the patch advisory. The exploit chain is three steps: upload a malformed GGUF via HTTP POST, trigger the read through the /api/create endpoint, exfiltrate the heap contents via /api/push. No authentication required." The vulnerability sits in Ollama's GGUF model loader. A crafted file with inflated tensor offset values causes the server to read beyond allocated heap boundaries — and what's in that heap is the problem. Separate Windows flaws compound this. CVE-2026-42248 and CVE-2026-42249 (both CVSS 7.7, currently unpatched) combine missing update binary signature verification with a path traversal that allows arbitrary executable placement in the Startup folder — persistent code execution at user privilege on every login. Confirmed leakable data includes environment variables, API keys, system prompts, concurrent users' conversation data, and proprietary code. The AI-specific risk: teams running Ollama in self-hosted or hybrid setups are often doing so specifically because they want to keep data on-premises. This vulnerability puts API keys, system prompts, and live conversation data in scope for anyone who can reach the endpoint. Immediate actions: patch to Ollama 0.17.1+, restrict network access to the instance, deploy an authentication proxy in front of the endpoint, and disable auto-updates on Windows until the signature verification flaw is patched. The deeper question: if your local LLM deployment leaks heap memory containing API keys and user conversation data, how much of your governance posture was actually on-premises? → Full CVE breakdown: http://thehackernews.com/2026/05/ollama-out-of-bounds-read-vulnerability.html → Proxy-layer protection docs: http://aisecuritygateway.ai/docs #LLMSecurity #AISecurity #AIGovernance #DataPrivacy #CyberSecurity

    Post summary

    The post announces a high‑severity out‑of‑bounds read in Ollama’s GGUF loader, details a functional three‑step exploit chain, and outlines patches and mitigations, emphasizing the significant data leakage risk.

    0000054
    39 followersView on X
  • tpx Security ⠠⠵@tpx_Security
    Disclosure

    "Bleeding Llama" (CVE-2026-7482) es una falla crítica en el framework Ollama que permite a atacantes remotos extraer de la memoria del servidor claves API, prompts y conversaciones de usuarios mediante la carga de archivos GGUF maliciosos. Además, dos vulnerabilidades aún sin parchear en su versión para Windows (CVE-2026-42248 y CVE-2026-42249) habilitan la ejecución silenciosa y persistente de código abusando del sistema de actualizaciones.

    Post summary

    Ollama’s framework has critical flaws—CVE‑2026‑7482 lets remote attackers harvest API keys and conversations from memory via malicious GGUF files, while CVE‑2026‑42248/42249 enable silent, persistent code execution on Windows through the update mechanism; no patches are yet available.

    0000091
    3.8K followersView on X
  • Cel Quintero 𝕏@Cel_Metal_
    Patch

    ⚠️ Using @ollama on Windows? Check your version. CVE-2026-42248 + CVE-2026-42249 (CVSS 7.7 each) Affected: 0.12.10 to 0.22.0 Patch status: UNPATCHED after 90 days of disclosure !! The patch was due yesterday, @ollama Cc. @StrigaAI @CERT_Polska

    Post summary

    CVE-2026-42248 and CVE-2026-42249 affect ollama Windows versions 0.12.10–0.22.0 and remain unpatched; the patch was overdue.

    0000038
    1.8K followersView on X
  • Shah Sheikh@shah_sheikh
    Disclosure

    Unpatched flaws turn Ollama’s auto-updater into a persistent RCE vector, researchers say: Researchers at Striga have disclosed two vulnerabilities (CVE-2026-42248, CVE-2026-42249) in Ollama’s Windows auto-updater that, when chained together, may allow an… https://www.helpnetsecurity.com/2026/05/05/ollama-windows-vulnerabilities-cve-2026-42248-cve-2026-42249/?utm_source=dlvr.it&utm_medium=twitter https://t.co/uHil0gL95B

    Post summary

    The article announces two newly disclosed CVEs in Ollama’s Windows auto‑updater that can be chained to achieve RCE, but it provides no PoC, exploit code, or patch information.

    0000059
    2.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows---
Appollamaollama---

Explore more