<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — GGUF</title><description>Articles on devtake.dev covering GGUF.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>A crafted Ollama model file leaks the whole server&apos;s memory. 300,000 instances are exposed.</title><link>https://devtake.dev/article/ollama-bleeding-llama-cve-2026-7482/</link><guid isPermaLink="true">https://devtake.dev/article/ollama-bleeding-llama-cve-2026-7482/</guid><description>Cyera disclosed CVE-2026-7482 on May 1, a CVSS 9.1 unauthenticated heap read in Ollama. Three API calls dump prompts, env vars, and API keys from any open instance.</description><pubDate>Mon, 11 May 2026 10:00:00 GMT</pubDate><category>security</category><category>security</category><category>ollama</category><category>llm</category><category>cve-2026-7482</category><category>local-inference</category><category>memory</category><category>cyera</category><category>ai-security</category><author>luca-reinhardt</author></item><item><title>A malicious GGUF file owns your SGLang server: CVE-2026-5760 is an unpatched 9.8</title><link>https://devtake.dev/article/sglang-cve-2026-5760-gguf-rce/</link><guid isPermaLink="true">https://devtake.dev/article/sglang-cve-2026-5760-gguf-rce/</guid><description>SGLang&apos;s reranker renders chat templates without a sandbox. Load a hostile GGUF, hit /v1/rerank, and the attacker has Python on your inference box. No patch yet.</description><pubDate>Mon, 27 Apr 2026 11:30:00 GMT</pubDate><category>security</category><category>sglang</category><category>cve-2026-5760</category><category>supply-chain</category><category>ai-security</category><category>llm</category><category>rce</category><category>jinja2</category><category>gguf</category><author>luca-reinhardt</author></item></channel></rss>