- EPSS -
- Veröffentlicht 26.06.2026 15:15:28
- Zuletzt bearbeitet 26.06.2026 16:16:36
Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy per...
- EPSS 1%
- Veröffentlicht 04.05.2026 12:38:28
- Zuletzt bearbeitet 11.05.2026 12:27:11
Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quant...
CVE-2026-42249
- EPSS 0.63%
- Veröffentlicht 29.04.2026 12:16:19
- Zuletzt bearbeitet 18.05.2026 18:23:25
Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the application constructs local file paths using values derive...
CVE-2026-42248
- EPSS 0.38%
- Veröffentlicht 29.04.2026 12:16:18
- Zuletzt bearbeitet 18.05.2026 18:22:55
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unconditionally returns success so no digital signature...
CVE-2026-7020
- EPSS 0.91%
- Veröffentlicht 26.04.2026 05:16:02
- Zuletzt bearbeitet 06.05.2026 06:16:08
A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path tra...
CVE-2026-5530
- EPSS 0.29%
- Veröffentlicht 05.04.2026 00:30:13
- Zuletzt bearbeitet 24.04.2026 18:13:28
A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remote...
CVE-2025-66959
- EPSS 4.55%
- Veröffentlicht 21.01.2026 00:00:00
- Zuletzt bearbeitet 02.02.2026 17:27:47
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder
CVE-2025-66960
- EPSS 0.36%
- Veröffentlicht 21.01.2026 00:00:00
- Zuletzt bearbeitet 02.02.2026 17:27:26
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata
CVE-2025-15514
- EPSS 0.64%
- Veröffentlicht 12.01.2026 23:03:52
- Zuletzt bearbeitet 21.01.2026 17:52:04
Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data via the /api/chat endpoint, the application fails to ...
CVE-2025-63389
- EPSS 0.63%
- Veröffentlicht 18.12.2025 00:00:00
- Zuletzt bearbeitet 22.01.2026 18:16:43
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform un...