CVE-2026-5757Disclosure(ollama / ollama)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (7 mentions)

Immediate actions

  • Patch ollama ollama systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

5.8/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-125

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ollama

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 20 mentions across 12 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 13 signals
  • Disclosure: 12 classified signals
  • General: 3 classified signals
  • Peaked at 7 mentions on most recent observed day (2026-06-04)
  • 20 total mentions across 12 days

Affected systems

Vendors
Products
ollama

Deep dive

Activity timeline20 mentions / 12d
02457Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-04-26: 2Mentions · 2026-04-27: 2Mentions · 2026-04-28: 1Mentions · 2026-04-30: 1Mentions · 2026-05-05: 1Mentions · 2026-05-06: 1Mentions · 2026-05-12: 1Mentions · 2026-05-16: 1Mentions · 2026-06-04: 7PoC Mentioned / Linked · 2026-04-24: 1Active Exploitation · 2026-04-30: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-04-27: 2Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-26: 1Technical Details · 2026-04-27: 2Technical Details · 2026-04-30: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-16: 1Technical Details · 2026-06-04: 404-2304-2404-2504-2604-2704-2804-3005-0505-0605-1205-1606-04
Signal classification5 categories
Disclosure
1260.0%
Patch
315.0%
General
315.0%
PoC
15.0%
Active Exploitation
15.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-04-241
PoC1
2026-04-251
Disclosure1
2026-04-262
Disclosure2
2026-04-272
Patch2
2026-04-281
General1
2026-04-301
Active Exploitation1
2026-05-051
Disclosure1
2026-05-061
Patch1
2026-05-121
Disclosure1
2026-05-161
Disclosure1
2026-06-047
Disclosure5General2
Full discourse20 posts
  • Sekurak@Sekurak
    Disclosure

    🚨Uwaga: Podatność w platformie Ollama umożliwia nieautoryzowany dostęp do pamięci serwera ⚠️ Luka (CVE-2026-5757) została wykryta przez badacza Jeremy Brown wspieranego przez narzędzia AI. 🛠️ Za pomocą odpowiednio spreparowanego pliku GGUF możliwy jest wyciek danych z pamięci operacyjnej serwera (klucze API, dane uwierzytelniające, itp.). 🔴 Na chwilę publikacji nie została wydana poprawka bezpieczeństwa. 🛡️ Zalecamy ograniczyć funkcję uploadu modeli oraz wdrożenie mechanizmów monitorujących ruch sieciowy. 👉 Szczegóły: https://sekurak.pl/powazna-podatnosc-w-platformie-ollama-prowadzi-do-wycieku-pamieci-a-wszystko-przez-odpowiednio-spreparowany-plik-gguf-cve-2026-5757/

    Post summary

    The post announces CVE-2026-5757 in Ollama, which enables memory leakage through crafted GGUF files; no patch is available yet and it recommends limiting uploads and monitoring traffic.

    1803774.9K
    43.9K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Unpatched CVE-2026-5757 in Ollama allows unauthenticated heap memory exfiltration via crafted GGUF files. No patch available—secure your LLM servers now. #Ollama #AI #LLM #CyberSecurity #InfoSec #CVE20265757 #ZeroDay #GGUF https://securityonline.info/ollama-heap-memory-leak-cve-2026-5757-zero-day/ https://t.co/jtNwZKOKcT

    Post summary

    The post discloses that CVE‑2026‑5757 in Ollama is an unpatched heap memory exfiltration vulnerability exploitable via crafted GGUF files, urging users to secure their LLM servers.

    140103869
    12.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Ollama GGUF quantization memory leak (CVE-2026-5757) A crafted GGUF model can trigger out-of-bounds memory access in Ollama’s quantization engine, allowing unauthenticated attackers to read heap memory and exfiltrate it via model layers. This may expose sensitive data and lead to further compromise. 👉 Restrict/disable model uploads and limit exposure to trusted environments

    Post summary

    Ollama’s GGUF quantization engine has a critical memory leak allowing unauthenticated read of heap memory; mitigate by restricting model uploads and limiting exposure to trusted environments.

    00040125
    237 followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 استغلال تحميلات نماذج Ollama لتسريب بيانات خادم حساسة تم اكتشاف ثغرة أمنية خطيرة لم يتم إصلاحها في Ollama، وهو منصة مفتوحة المصدر شائعة لتشغيل نماذج اللغة الكبيرة محليًا. تسمح هذه الثغرة، التي تم تتبعها كـ CVE-2026-5757، بتسرب ذاكرة خطير يمكّن المهاجمين من استغلال تحميلات نماذج Ollama لتسريب بيانات خادم حساسة. يُنصح بـ تطبيق التصحيحات الأمنية فور توفرها. 🔗 للمزيد: https://cybersecuritynews.com/hackers-exploit-ollama-model/

    Post summary

    The article reports an unpatched memory‑leak vulnerability (CVE-2026-5757) in Ollama and urges users to apply available patches.

    00030705
    268 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Ollama's GGUF quantization engine contains a critical out-of-bounds memory read vulnerability (CVE-2026-5757, CVSS 8.6) that allows unauthenticated attackers to steal sensitive server heap data—including API keys, user credentials, and proprietary AI training data—by…

    Post summary

    The passage announces the discovery of a critical out‑of‑bounds memory read vulnerability (CVE‑2026‑5757) in Ollama’s GGUF quantization engine that could let unauthenticated attackers read sensitive server data. No details on patches, PoC, or active exploitation are provided.

    1010073
    239 followersView on X
  • 児玉です@makodama
    Disclosure

    【警告】ローカルAI利用者は今すぐ設定を確認してください。 人気のLLM実行ツール「Ollama」に、極めて深刻な脆弱性(CVE-2026-5757)が発見されました。 「ローカルだから安全」という油断が、あなたのPCを最大のセキュリティホールに変える可能性があります。 🚨 現状のヤバいポイント ・境界外読み取り/書き込みの脆弱性が判明 ・現時点で公式パッチ(修正プログラム)は未配布 ・外部公開しているサーバーは特に対象 この脆弱性が悪用されると、メモリ上のデータが盗まれたり、システムが不正操作されるリスクがあります。特に開発環境や社内サーバーでOllamaを動かしている方は、一刻を争う事態です。 💡 今すぐすべき暫定対策 1. Ollamaサービスをインターネットに直接公開しない 2. ファイアウォールでアクセス可能なIPを厳格に制限 3. ローカルホスト(127.0.0.1)のみで待機する設定を徹底 「自分は大丈夫」という思い込みが一番危険です。最新のパッチが出るまで、外部からのアクセス経路を完全に遮断することを強く推奨します。 皆さんのローカル環境、セキュリティ設定は万全ですか? 他に有効な対策を知っている方がいれば、ぜひリプ欄で共有してください。情報を集約しましょう。 詳細はリプ欄のリンクから👇 #Ollama #AIセキュリティ

    Post summary

    The post announces a serious CVE‑2026‑5757 affecting Ollama, emphasizes the lack of an official patch, and recommends practical mitigations until a fix is released.

    10010195
    3.7K followersView on X
  • Agent Community@agentcommunity_
    Patch

    @sama @AISecurityInst @rohanpaul_ai @OpenAIDevs @koltregaskes @ainativedev @daniel_mac8 @stripe @tempo @altryne @ChainBountyX @ivanburazin @BeauJohnson89 @PrimeIntellect @SakanaAILabs @jerryjliu0 @aakashgupta @tom_doerr @SemiAnalysis_ @theo The "Bleeding Llama" (CVE-2026-5757) vulnerability has put 300,000 Ollama deployments on notice. Builders are pivoting toward hardened infrastructure and token-saving proxies that cut consumption by 60-90%.

    Post summary

    The post highlights that the newly disclosed CVE-2026-5757 has alerted hundreds of thousands of Ollama deployments and that developers are adopting hardened infrastructure and token‑saving proxies as a mitigation. No exploit code or active exploitation evidence is reported.

    1001072
    1.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Ollama's GGUF quantization engine contains a critical out-of-bounds memory read vulnerability (CVE-2026-5757, CVSS 8.6) that allows unauthenticated attackers to steal sensitive server heap data—including API keys, user credentials, and proprietary AI training data—by…

    Post summary

    The post announces a critical out-of-bounds read flaw (CVE-2026-5757, CVSS 8.6) in Ollama’s GGUF quantizer that could let attackers harvest server heap data, but it lacks exploit code, active use sightings, or patch information.

    1000063
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Lyrie's autonomous defense mission is to detect and block attacks faster than humans can respond. But CVE-2026-5757 breaks the detection paradigm entirely: Traditional network detection (IDS/IPS) sees only GGUF upload and normal model registry traffic. EDR/behavioral…

    Post summary

    The post notes that CVE‑2026‑5757 breaks detection systems but offers no evidence of PoC, exploit, patch or active use.

    1000044
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Model That Leaked Your Secrets: CVE-2026-5757 Turns Ollama Into a Memory Exfiltration Engine Ollama's GGUF quantization engine contains a critical out-of-bounds memory read vulnerability CVE-2026-5757, CVSS 8.6 that allows unauthenticated attackers to steal sensitive…

    Post summary

    The text announces CVE-2026-5757, an out‑of‑bounds memory read flaw in Ollama’s GGUF quantization engine with a CVSS of 8.6, noting its potential for unauthenticated data exfiltration, but provides no evidence of active exploitation, PoC, or fixes.

    1000097
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-5757 · 8.6 → 0.17.0 The Model That Leaked Your Secrets: CVE-2026-5757 Turns Ollama Into a Memory Exfiltration Engine

    Post summary

    The snippet references CVE-2026-5757 and hints that it turns Ollama into a memory exfiltration engine, but provides no actionable technical, exploit, or mitigation details.

    1000076
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Model That Leaked Your Secrets: CVE-2026-5757 Turns Ollama Into a Memory Exfiltration Engine. Ollama's GGUF quantization engine contains a critical out-of-bounds memory read vulnerability CVE-2026-5757, CVSS 8.6 that allows unauthenticated attackers to steal sensitive…

    Post summary

    The text reports the discovery of CVE‑2026‑5757, an out‑of‑bounds memory read in Ollama's GGUF quantization engine that could enable memory exfiltration, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    1000094
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    What this means for your agents and systems: The Model That Leaked Your Secrets: CVE-2026-5757 Turns Ollama Into a Memory Exfiltration Engine

    Post summary

    The headline announces that CVE‑2026‑5757 turns Ollama into a memory exfiltration engine, but it offers no further technical details or mitigation guidance.

    1000081
    239 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    Ollama の脆弱性 CVE-2026-5757: GGUF ファイル処理とメモリ破壊 https://iototsecnews.jp/2026/04/24/hackers-exploit-ollama-model-uploads-to-leak-server-data/ この問題の原因は、AI モデルのサイズを軽量化する量子化という処理の過程で、プログラムが読み込むデータの正確さを十分に確認していなかったことにあります。具体的には CVE-2026-5757 として識別されており、攻撃者が特別に細工したモデルファイルを読み込ませることで、本来アクセスしてはいけないサーバー内のメモリ領域を覗き見できる状況に陥ります。さらに、このプログラムの一部では、メモリを直接操作して安全性の確認を困難にする手法が使われているため、メモリに一時的に保存されていた API キーや機密データが、新しいモデルデータの一部として外部に漏れ出してしまう危険があります。ご利用のチームは、ご注意ください。 #CVE20265757 #LLM #Ollama #Vulnerability

    Post summary

    CVE-2026-5757 enables attackers to read restricted memory and leak API keys via malicious GGUF model files; attackers are already exploiting this in real‑world attacks.

    0100098
    485 followersView on X
  • Rupom Ghosh@rupomkghosh
    Patch

    URGENT for local LLM users: Stop uploading untrusted GGUF files to Ollama. CVE-2026-5757 was just disclosed. It’s a critical memory leak in the quantization engine that lets attackers scrape your server’s heap. If you’re running local AI without strict file validation, your API keys and private data are sitting in the "danger zone." Performance is great, but security is the only thing that keeps you in business. Patch your workflows now.

    Post summary

    The newly disclosed CVE‑2026‑5757 is a critical memory leak in Ollama’s quantization engine that could expose heap data; users are urged to patch immediately.

    0100053
    61 followersView on X
  • hogehoge06@hogehoge1878
    Disclosure

    ローカル環境で大規模言語モデル(LLM)を実行するオープンソースツール「Ollama」に境界外読み取り・書き込みの脆弱性(CVE-2026-5757)  この脆弱性はベンダーに報告されたものの、いまだ対策パッチは提供されていない。 https://forest.watch.impress.co.jp/docs/news/2107734.html

    Post summary

    A newly reported CVE‑2026‑5757 out‑of‑bounds read/write vulnerability was identified in the open‑source LLM tool Ollama. Vendor remediation is pending, with no patch yet released.

    0000088
    187 followersView on X
  • くりとグラの聴くサイバー防衛ラジオ@KuriGCyberRadio
    General

    https://youtu.be/d2JCg0-ceno Ollamaに潜むデータ漏洩リスク:CVE-2026-5757 Ciscoファイアウォール生存マルウェア「Firestarter」の脅威 WordPressプラグイン重大脆弱性:Breeze Cache任意ファイルアップロードについて

    Post summary

    The text mentions several CVEs and threats but provides no concrete details, fixes, or exploitation evidence.

    00000133
    2 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-5757: Ollama Flaw Leaks Server Heap Memory Remotely https://thecybrdef.com/cve-2026-5757-ollama-memory-leak-vulnerability/ #CVE20265757 #Ollama #CyberSecurity

    Post summary

    The post announces the CVE-2026-5757 vulnerability in Ollama, highlighting a server‑heap memory leak that can be triggered remotely, but it does not provide PoC, exploit details, or mitigation steps.

    0000051
    7 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-5757: Ollama Flaw Leaks Server Heap Memory Remotely https://thecybrdef.com/cve-2026-5757-ollama-memory-leak-vulnerability/

    Post summary

    The article announces a memory‑leak vulnerability in Ollama that allows remote heap memory leakage, but it contains no PoC, exploit code, or patch information.

    0000067
    6 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 Critical Zero-Day #AI Attack: #CVE-2026-5757 Exposes Secret Data Through Poisoned LLM Uploads + Video https://undercodetesting.com/critical-zero-day-ai-attack-cve-2026-5757-exposes-secret-data-through-poisoned-llm-uploads-video/ Educational Purposes!

    Post summary

    The tweet announces a critical zero‑day CVE‑2026‑5757 that allegedly leaks data through poisoned LLM uploads, linking to an article that appears to provide a proof‑of‑concept video, but it offers no exploit code, patch information, or evidence of active exploitation.

    00000106
    497 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appollamaollama---

Explore more