
Security·
A crafted Ollama model file leaks the whole server's memory. 300,000 instances are exposed.
Cyera disclosed CVE-2026-7482 on May 1, a CVSS 9.1 unauthenticated heap read in Ollama. Three API calls dump prompts, env vars, and API keys from any open instance.
