By vendor
Ollama vulnerabilities
Known CVEs affecting Ollama products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-5757HIGH 7.5
A remote attacker can read sensitive data directly from an Ollama server's memory without needing to log in. The vulnerability exists in how Ollama processes model quantization requests, allowing an unauthenticated person on the network to extract heap memory contents. This could expose API keys, model weights, user data, or other confidential information stored in the server process, potentially enabling lateral movement or persistent backdoor installation.