CVE-2026-65315: Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows r
Summary
Ollama (a tool for running AI models locally) has a vulnerability in its GGUF metadata parser (the code that reads model file headers) that allows attackers to crash the server by uploading a specially crafted model file with fake size information. The parser doesn't check if the claimed sizes match the actual file, so it tries to allocate huge amounts of memory and crashes the entire server.
Vulnerability Details
7.5(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
network
low
none
none
July 21, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-65315
First tracked: July 22, 2026 at 02:07 AM
Classified by LLM (prompt v3) · confidence: 95%