Ollama, a popular open-source framework for running large language models (LLMs) locally, has been hit by a critical security vulnerability. This vulnerability, dubbed Bleeding Llama by Cyera, allows a remote, unauthenticated attacker to leak the entire process memory of an exposed Ollama server. The issue stems from an out-of-bounds read flaw in the GGUF model loader, which is a file format used to store and load LLMs. This vulnerability, tracked as CVE-2026-7482 with a CVSS score of 9.1, impacts over 300,000 servers globally. The problem arises from Ollama's use of the unsafe package when creating models from GGUF files, specifically in the 'WriteTo()' function. This allows attackers to execute operations that bypass the memory safety guarantees of the programming language. In a hypothetical attack scenario, a bad actor can send a specially crafted GGUF file to an exposed Ollama server, triggering an out-of-bounds heap read during model creation. This can lead to the exfiltration of sensitive data from the Ollama process memory, including environment variables, API keys, system prompts, and concurrent users' conversation data. The exploitation chain involves uploading a crafted GGUF file, triggering the vulnerability via the '/api/create' endpoint, and then exfiltrating data via the '/api/push' endpoint to an external server. This vulnerability is particularly concerning given the potential for attackers to gain access to sensitive organizational data, including API keys and proprietary code. The situation is made worse by the fact that Ollama is often connected to tools like Claude Code, which can further amplify the impact of the attack. To mitigate this vulnerability, users are advised to apply the latest fixes, limit network access, audit and secure running instances, and deploy an authentication proxy or API gateway. The development of Ollama has also been marred by two unpatched vulnerabilities in its Windows update mechanism, which can be chained into persistent code execution. These vulnerabilities, detailed by Striga, involve a path traversal and a missing signature check. They allow an attacker to influence update responses and execute arbitrary code at every login, even after the next legitimate update overwrites the staged file. The vulnerabilities are tracked as CVE-2026-42248 and CVE-2026-42249, with CVSS scores of 7.7. To protect against these vulnerabilities, users are recommended to turn off automatic updates and remove Ollama shortcuts from the Windows Startup folder. These issues highlight the ongoing challenges in securing open-source software and the importance of prompt patching and user vigilance.
Critical Security Flaws in Ollama: Remote Memory Leak and Persistent Code Execution (2026)
References
- Can you pay rent with a credit card?
- Zero 1.0 Released: Rocicorp's Web Sync Engine Reaches Stability - What's New?
- Nelly Korda's Dramatic Win at the US Women's Open: A Birdie for the Ages
- Emergency Landing: Aurigny Flight GR678's Windscreen Cracks
- Zero 1.0 Released: Rocicorp's Web Sync Engine Reaches Stability - What's New?
- Stanley Cup Fill-up: Triangle Ice Cream Shop Supports Canes in Game 4
- Revolutionizing X-Ray Protection: Lighter Aprons for Health Workers
- India's Declining Birth Rate: The Future of Work and Family
- Australian Dollar Plummets: Interest Rate Fears & Global Market Impact Explained
- Michael Olise's Road to World Cup Stardom: A Gael Clichy Perspective
- Who really owns your iPhone? The dark side of digital ownership
- Japanese City Shuts Down Schools After Bear Sighting
- Emotional Rugby Goodbyes & Shock Upsets! | Wales Coach, County Champs, URC Drama!
- China Box Office: Top Movies of June 2026 | Family Drama, Crime Thriller, and Sci-Fi
- Nelly Korda Wins Maiden US Women's Open! Dramatic Finish vs Charley Hull
- The Changing Spending Habits: A Look at the Latest Data
- Emotional Rugby Goodbyes & Shock Upsets! | Wales Coach, County Champs, URC Drama!
- Top Chefs Back Andy Burnham for Prime Minister: Cut VAT on Hospitality
- Megan Thee Stallion, P!NK, and Neil Patrick Harris' Epic 'Lady Marmalade' Performance at the Tonys
- Remembering Neale Daniher: The Impact of the Big Freeze Event at the MCG
- Jose Mourinho Returns to Real Madrid! Florentino Perez Re-Elected as President | Football News
- Newbury's Literary Legacy: Unveiling the Town's New Mural
- 2026 Free Agents: Top 10 Transfers Predictions | Premier League, MLS & More
- Philippines Earthquake: Devastation and Rescue Efforts
- Ports Rumble Over Quakes for a 15-8 Win! | Stockton Ports vs Ontario Tower Buzzers Highlights
- 2026 Free Agents: Top 10 Transfers Predictions | Premier League, MLS & More
- 2026 Free Agents: Top 10 Transfers Predictions | Premier League, MLS & More
- Is Your Fear a Phobia? Signs and Treatment
- Inflation's Impact: Why People Spend More on Necessities and Less on Luxuries
- Samsung Galaxy S26: Adaptive Performance Profile for Enhanced Battery Life
- Queen Maxima's Stunning Citrine Pineapple Earrings: Royal Jewelry Breakdown
- Queen Maxima's Yellow Ensemble: Citrine Pineapples and Pearls
- ScottishPower's Insensitivity: Sending Cheques to the Deceased
- Indian Kids' Leukemia Treatment: Steroid Tweak Reduces Early Deaths
- Nuclear Weapons Focus Amid Escalation Risks: SIPRI Yearbook 2026
- Norwich City Council Allocates £564k for Historic Church Restoration
- Deep-Sea Supergiant Isopod: Surviving 5 Years Without Food | Unlocking the Mystery
- Carven Appoints Kai Nesselrath as Design Director
- Remembering Robert Coles: The Legacy of a Pulitzer-Winning Psychiatrist
- Bernardo Silva's Family Life: From Dogs to a Growing Family
- Gaokao 2026: China's College Entrance Exam | Day 2 - English Test
- M25 Traffic Chaos: Lorry Crash Causes Massive Delays
- What's on the Economic Agenda Today? European and American Sessions Preview
- Top Chefs Back Andy Burnham for Prime Minister: Cut VAT on Hospitality
- Ports Rumble Over Quakes for a 15-8 Win! | Stockton Ports vs Ontario Tower Buzzers Highlights
- Aziaha James Returns to Dallas Wings Practice After Injury Scare vs. LA Sparks | WNBA Update
- Unleash the Power of Cinnamon: The Secret Ingredient for a Healthier Coffee
- Emotional Rugby Goodbyes & Shock Upsets! | Wales Coach, County Champs, URC Drama!
- Scrappage Scheme: Environmental Trade-offs of EV Incentives
- Silver Price Plunge: What's Causing the Sell-Off and Where is it Heading?
- Is 'Scary Movie' the Ultimate Legacy Sequel Parody? | Horror Comedy Review
- Revolutionary Spectroscopy Technique Reveals Hidden Secrets of Air-Water Interfaces
- ScottishPower's Insensitivity: Sending Cheques to the Deceased
- Hong Kong's Data Centers: High Carbon Footprint and Energy Consumption
- ScottishPower's Insensitivity: Sending Cheques to the Deceased
- Global Markets React: Tech Sell-Off, Interest Rate Hike Fears, and Geopolitical Tensions
- 2026 Free Agents: Top 10 Transfers Predictions | Premier League, MLS & More
- OPEC+ Oil Output Hike: What It Means for Global Oil Prices & the Middle East Crisis
- Solis Energy Storage Revolution: Unveiling the Future of Power
- Deniz Undav Breaks Down Lennart Karl's Injury: A Youngster's World Cup Dream Shattered
- Indonesian Rupiah Crisis: Why It’s Hitting Historic Lows & What It Means for the Global Economy
- VS Code Adds 2-Hour Extension Auto-Update Delay: Protecting Against Supply Chain Attacks
- Queen Maxima's Yellow Ensemble: Citrine Pineapples and Pearls
- Emergency Landing: Aurigny Flight GR678 Cracked Windscreen | Southampton Airport
- Zero 1.0 Released: Rocicorp's Web Sync Engine Reaches Stability - What's New?
- Europe vs. US Tech: Why Europe is Ditching American Technology
- Supporting Regional Theatre: The Importance of New Work and Collaboration
- China's Box Office Hits: 'Dear You' Reigns, 'Vanishing Point' Thrills
- Airline Industry Leaders: 2050 Net Zero Goal Unlikely - What Went Wrong?
- Christian Eriksen's Health Update: Doing Well After On-Field Collapse
- Unveiling the Secrets of Water-Air Interfaces: A New Spectroscopy Technique
- Who Really Owns Your iPhone? The Dark Side of Digital Ownership
- Pikmin Bloom x Shinji Okazaki: A Walk with a Football Legend
- The Environmental Impact of EV Scrappage Schemes
- Lennart Karl's World Cup Dreams Shattered: Injury Heartbreak for Germany's Youngster
- The Final Chapter: Sagrada Família's Tower of Jesus Christ Unveiled
- The Impact of Hidden Costs on Airline Fares: A Look at the Latest Trends
- Gold Price in India Plummets: June 8th Update & What It Means for Investors
- Ports Rumble Over Quakes for a 15-8 Win! | Stockton Ports vs Ontario Tower Buzzers Highlights
- Ports Rumble Over Quakes for a 15-8 Win! | Stockton Ports vs Ontario Tower Buzzers Highlights
- Trinamool Crisis: MP Sukhendu Sekhar Ray Resigns Amid Party Mutiny
- What to Do if a Family Member is a Dangerous Driver | Expert Advice
- Britain's Economic Outlook: Insights from the Bank of England
- What to Do if a Family Member is a Dangerous Driver | Expert Advice
- Unleash the Power of Cinnamon: The Secret Ingredient for a Healthier Coffee
- Iyabo Obasanjo's Political Journey: From APC Resignation to Allegations of Disrespect
- Norwich City Council Allocates £564k for Historic Church Restoration
- SFO Ground Stop: What Happened and Why It Matters
- The Changing Spending Habits: A Look at the Latest Data
- Unleash the Power of Cinnamon: The Secret Ingredient for a Healthier Coffee
- Rodmell Water Crisis: Residents Demand Answers from South East Water
- UK PM Keir Starmer's Vision: AI Revolution & Online Safety for Children
- Victorian Curriculum 2.0: What’s Changing for Prep Students in 2027? | Education Reform Explained
- AI vs Fraud: Aviva's Battle Against Bogus Insurance Claims
- Ports Rumble Over Quakes for a 15-8 Win! | Stockton Ports vs Ontario Tower Buzzers Highlights
- Philippines Earthquake: 7.8 Magnitude Quake Strikes, Triggering Tsunami Warnings
- WA Opposition Leader Basil Zempilas Considers Working with One Nation: A Shift in Politics?
- Steven Spielberg on Eve Hewson's Performance in 'Disclosure Day'
- Devon Dad's Epic 10-Lake Swim in Switzerland: Raising Awareness for PANDAS
- Transforming a Victorian Terrace: A Calm and Stylish Family Home in London
- ナヒーダ 中出しえっち
Author: The Hon. Margery Christiansen
Last Updated:
Views: 5614
Rating: 5 / 5 (50 voted)
Reviews: 89% of readers found this page helpful
Name: The Hon. Margery Christiansen
Birthday: 2000-07-07
Address: 5050 Breitenberg Knoll, New Robert, MI 45409
Phone: +2556892639372
Job: Investor Mining Engineer
Hobby: Sketching, Cosplaying, Glassblowing, Genealogy, Crocheting, Archery, Skateboarding
Introduction: My name is The Hon. Margery Christiansen, I am a bright, adorable, precious, inexpensive, gorgeous, comfortable, happy person who loves writing and wants to share my knowledge and understanding with you.