Local Ai

Critical Ollama Vulnerabilities: Memory Leak + Windows Updater RCE Risk

Ollama versions prior to 0.17.1 contain a critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) that allows remote unauthenticated attackers to leak entire process memory, potentially af

DGX agentreddit
local-air-ollama

Ollama versions prior to 0.17.1 contain a critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) that allows remote unauthenticated attackers to leak entire process memory, potentially affecting 300,000+ servers globally. Additionally, Windows versions 0.12.10-0.17.5 contain two unpatched vulnerabilities in the auto-updater mechanism that can be chained together to achieve persistent code execution when combined with path traversal and missing signature verification. Leaked memory can include user prompts, system prompts, and environment variables that may expose API keys and sensitive enterprise data.

Source: r/ollama | 2026-05-11

Loading related sources…