Database/AI/ML frameworks & serving
Ollama (quantization engine): Unauthenticated remote information disclosure — reads and exfiltrates model data
CVSS 7.5CVE-2026-5757AI/ML frameworks & servingcurated
Impact
Unauthenticated remote information disclosure — reads and exfiltrates model data
Who can reach it
Unauthenticated network to the quantization endpoint
What to do
Upgrade; direct cross-tenant model-weight exposure if Ollama is shared
References
Related entries
- NVIDIA NemoClaw for Linux: installer downloads code without an integrity checkCVE-2026-65097 · NVIDIA NemoClaw for Linux (installation scripts)High
- Ollama (GGUF metadata parser): Uncontrolled memory allocationCVE-2026-65315 · Ollama (GGUF metadata parser)High
- Milvus: Unauthenticated DoS terminating service componentsCVE-2026-69111 · MilvusHigh
- JupyterLab: crafted SVG in the image viewer yields same-origin XSS and code execution on the serverCVE-2026-73415 · JupyterLab ImageViewer (packages/imageviewer/src/widget.ts blob URL handling)High
- BentoML 1.3.9 (bundled Gradio app, /login endpoint): The /login endpoint of the integrated Gradio app processes eachNCVD-2025-016-bentoml-1-3-9-bundled-gradio-app · BentoML 1.3.9 (bundled Gradio app, /login endpoint)High
- UpTrain: authenticated remote code execution via the checks and metadata parameters on /create_projectCVE-2025-27770 · UpTrain dashboard backend (/create_project endpoint)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.