A vulnerability in the Ollama quantization engine (CVE not specified) allows a remote, anonymous attacker to disclose information, with a CVSS base score of 7.5. The article states a mitigation is available but does not provide specific affected version ranges, a fixed version number, or a workaround.
[WID-SEC-2026-2105] Ollama (Quantization Engine): Schwachstelle ermöglicht Offenlegung von Informationen CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.7 (mittel) Remoteangriff ja Datum 28.06.2026 Stand 29.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Windows Produktbeschreibung Ollama ist eine Open-Source-Runtime zum lokalen Ausführen von Large Language Models (LLMs) Produkte 28.06.2026 Ollama Ollama Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ollama ausnutzen, um Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben