CVE-2026-42248 — Ollama Ollama: for Windows does not perform integrity or authenticity verification of downloaded update executables.
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unconditionally returns success so no digital signature or trust validation is performed before staging or executing update payloads, enabling attacker‑supplied executables to be accepted and later executed by the application. Critically, Ollama for Windows performs silent automatic CVSSv3.1 9.8 (CRITICAL) · EPSS 1th percentile