CVE-2026-5757: There exists an unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine
Published Jun 26, 2026
·Updated
Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.
Affected Software
2 affected components
Ollama
Ollama Ollama<=0.13.5
Event History
Jun 26, 2026
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-5757?
CVE-2026-5757 has a risk score of 71, indicating a significant potential impact.
2
What does CVE-2026-5757 allow an attacker to do?
CVE-2026-5757 allows an attacker to unauthenticated read and exfiltrate the server's heap memory.
3
How can I fix CVE-2026-5757?
To fix CVE-2026-5757, upgrade to the latest version of Ollama that addresses this vulnerability.
4
What type of vulnerability is CVE-2026-5757 classified as?
CVE-2026-5757 is classified as an unauthenticated remote information disclosure vulnerability.
5
What can happen if CVE-2026-5757 is exploited?
Exploitation of CVE-2026-5757 can lead to sensitive data exposure and potential further compromise of the server.