CVE-2026-5757: Ollama

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

Affected products

  • Ollama Ollama: up to and including 0.13.5

Published 2026-06-26. Last modified 2026-06-29.