CVE-2026-65315
- EPSS 0.57%
- Veröffentlicht 21.07.2026 21:18:24
- Zuletzt bearbeitet 22.07.2026 20:40:02
Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string le...
CVE-2026-15685
- EPSS 0.39%
- Veröffentlicht 13.07.2026 21:30:09
- Zuletzt bearbeitet 14.07.2026 20:59:10
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit ...
CVE-2026-5757
- EPSS 0.55%
- Veröffentlicht 26.06.2026 15:15:28
- Zuletzt bearbeitet 29.06.2026 13:49:03
Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy per...
- EPSS 1.93%
- Veröffentlicht 04.05.2026 12:38:28
- Zuletzt bearbeitet 11.05.2026 12:27:11
Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quant...
CVE-2026-42249
- EPSS 0.63%
- Veröffentlicht 29.04.2026 12:16:19
- Zuletzt bearbeitet 18.05.2026 18:23:25
Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the application constructs local file paths using values derive...
CVE-2026-42248
- EPSS 0.38%
- Veröffentlicht 29.04.2026 12:16:18
- Zuletzt bearbeitet 18.05.2026 18:22:55
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unconditionally returns success so no digital signature...
CVE-2026-7020
- EPSS 0.91%
- Veröffentlicht 26.04.2026 05:16:02
- Zuletzt bearbeitet 06.05.2026 06:16:08
A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path tra...
CVE-2026-5530
- EPSS 0.3%
- Veröffentlicht 05.04.2026 00:30:13
- Zuletzt bearbeitet 24.07.2026 09:10:00
A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remo...
CVE-2025-66959
- EPSS 4.63%
- Veröffentlicht 21.01.2026 00:00:00
- Zuletzt bearbeitet 02.02.2026 17:27:47
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder
CVE-2025-66960
- EPSS 0.37%
- Veröffentlicht 21.01.2026 00:00:00
- Zuletzt bearbeitet 02.02.2026 17:27:26
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata