在 Ollama 版本 0.31.1 及更早版本中发现了一个安全漏洞。该问题影响了 GGUF 解码器组件中 文件里的 函数。通过对相关数据进行操作,会导致整数溢出漏洞。该漏洞可被远程利用。利用该漏洞的代码(exploit)已被公开,因此该漏洞可能被实际利用。将版本升级到 0.31.2-rc1 可以解决此问题。该修复补丁的标识为 。建议用户升级受影响的组件至修复版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Ollama | 0.31.0 |
cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86271 | 4.7 MEDIUM | FluentCMS PermissionManager.cs GetAccessible authorization |
| CVE-2026-86285 | 4.3 MEDIUM | BookStack Attachment Edit Endpoint AttachmentController.php getUpdateForm access control |
| CVE-2026-86244 | 4.3 MEDIUM | FastAdmin User Controller User.php login cross site scripting |
No comments yet