CVE-2026-86289: A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/g
Summary
A vulnerability was discovered in Ollama software up to version 0.31.1 that allows an integer overflow (a situation where a number calculation exceeds the maximum value a program can store, causing it to wrap around) in the GGUF Decoder component (the part that reads model files). An attacker can remotely exploit this vulnerability, and the exploit code has been made public.
Solution / Mitigation
Upgrading to version 0.31.2-rc1 is capable of addressing this issue. The patch is named 67b6a1c2d45321e0cb3c04a18073f9818de7724b.
Vulnerability Details
4.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
network
low
none
required
September 7, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86289
First tracked: September 7, 2026 at 08:06 AM
Classified by LLM (prompt v3) · confidence: 85%