Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 07 Sep 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.31.2-rc1 is capable of addressing this issue. The patch is named 67b6a1c2d45321e0cb3c04a18073f9818de7724b. It is recommended to upgrade the affected component. | |
| Title | Ollama GGUF Decoder gguf.go readGGUFV1String integer overflow | |
| First Time appeared |
Ollama
Ollama ollama |
|
| Weaknesses | CWE-189 CWE-190 |
|
| CPEs | cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ollama
Ollama ollama |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-07T08:45:15.290Z
Reserved: 2026-09-06T15:44:05.664Z
Link: CVE-2026-86289
No data.
Status : Received
Published: 2026-09-07T09:17:17.470
Modified: 2026-09-07T09:17:17.470
Link: CVE-2026-86289
No data.
OpenCVE Enrichment
Updated: 2026-09-07T14:00:17Z