Briefing

Critical Vulnerability in Ollama Could Leak Entire Process Memory (CVE-2026-7482)

security
by [email protected] (The Hacker News) · Llama CVE-2026-7482

Upgrade Ollama immediately to the patched version that resolves CVE‑2026‑7482.

What to do now

Upgrade Ollama immediately to the patched version that resolves CVE‑2026‑7482.

Summary

Cybersecurity researchers have uncovered a critical out‑of‑bounds read flaw in the popular Ollama AI model serving platform. The vulnerability, tracked as CVE‑2026‑7482, allows a remote, unauthenticated attacker to read the entire process memory of an Ollama instance, potentially exposing sensitive data and secrets. The flaw is rated CVSS 9.1 and is estimated to affect more than 300,000 servers worldwide that run the current release of Ollama. Cyera has dubbed the issue “Bleeding Llama” in reference to the model’s name. The exploit requires no authentication and can be triggered by sending a crafted request to the Ollama API. Ollama’s developers have acknowledged the issue and are working on a patch, but no release date has been announced yet. Users running Ollama should monitor vendor advisories and apply the fix as soon as it becomes available. Failure to patch could expose entire process memory to attackers, compromising confidential data and model weights.

Key changes

  • CVE‑2026‑7482 is an out‑of‑bounds read flaw in Ollama.
  • It allows a remote, unauthenticated attacker to read the entire process memory.
  • The flaw is rated CVSS 9.1 and could affect >300,000 servers worldwide.
  • The issue is named Bleeding Llama by Cyera.
  • The exploit requires no authentication and can be triggered via a crafted Ollama API request.
  • Ollama developers are working on a patch but no release date announced yet.
  • Users should monitor advisories and apply the fix promptly.
  • Failure to patch could expose confidential data and model weights.

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting