PatchSiren

Ollama AI CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Ollama AI CVE published 2026-06-26

CVE-2026-5757

CVE-2026-5757 is an unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine. This vulnerability allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CVE was published on June [truncated]