CVE-2026-7482 Affecting k8sgpt package, versions <0.4.33-r0


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
1.93% (78th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-WOLFILATEST-K8SGPT-16700998
  • published15 May 2026
  • disclosed4 May 2026

Introduced: 4 May 2026

CVE-2026-7482  (opens in a new tab)

How to fix?

Upgrade Wolfi k8sgpt to version 0.4.33-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream k8sgpt package and not the k8sgpt package as distributed by Wolfi. See How to fix? for Wolfi relevant fixed versions and status.

Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quantization in fs/ggml/gguf.go and server/quantization.go (WriteTo()), the server reads past the allocated heap buffer. The leaked memory contents may include environment variables, API keys, system prompts, and concurrent users' conversation data, and can be exfiltrated by uploading the resulting model artifact through the /api/push endpoint to an attacker-controlled registry. The /api/create and /api/push endpoints have no authentication in the upstream distribution. Default deployments bind to 127.0.0.1, but the documented OLLAMA_HOST=0.0.0.0 configuration is widely used in practice (large public-internet exposure observed).