---
id: CVE-2026-5757
title: >-
  Unauthenticated remote information disclosure vulnerability in Ollama's model
  quantization engine allows an attacker to read and exfiltrate the server's
  heap memory, potentially leading to sensitive data exposure, further
  compromise, and…
summary: >-
  Unauthenticated remote information disclosure vulnerability in Ollama's model
  quantization engine allows an attacker to read and exfiltrate the server's
  heap memory, potentially leading to sensitive data exposure, further
  compromise, and…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-125
published: '2026-06-26'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5757'
references:
  - url: 'https://kb.cert.org/vuls/id/518910'
    label: cret@cert.org
  - url: 'https://ollama.com'
    label: cret@cert.org
  - url: 'https://www.kb.cert.org/vuls/id/518910'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00735
epssPercentile: 0.52567
ingestedAt: '2026-06-29T14:29:18.116Z'
---

## Overview

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
