CVE-2026-103663
- EPSS 0.71%
- Veröffentlicht 08.10.2026 13:19:04
- Zuletzt bearbeitet 08.10.2026 20:08:45
Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by the `digestToPath` function. An unauthenticated remote attacker can specify a path traversal sequence as a layer digest, causing a m...
CVE-2026-102697
- EPSS 0.15%
- Veröffentlicht 29.09.2026 17:17:08
- Zuletzt bearbeitet 29.09.2026 21:32:59
Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injec...
- EPSS 0.4%
- Veröffentlicht 07.09.2026 08:45:15
- Zuletzt bearbeitet 11.09.2026 21:17:43
A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible to be carried ...
CVE-2026-85180
- EPSS 0.29%
- Veröffentlicht 03.09.2026 14:12:19
- Zuletzt bearbeitet 10.09.2026 15:47:22
Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifest, and cause ...
CVE-2026-65315
- EPSS 0.57%
- Veröffentlicht 21.07.2026 21:18:24
- Zuletzt bearbeitet 22.07.2026 20:40:02
Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string le...
CVE-2026-15685
- EPSS 0.39%
- Veröffentlicht 13.07.2026 21:30:09
- Zuletzt bearbeitet 14.07.2026 20:59:10
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit ...
CVE-2026-5757
- EPSS 0.55%
- Veröffentlicht 26.06.2026 15:15:28
- Zuletzt bearbeitet 29.06.2026 13:49:03
Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy per...
- EPSS 1.93%
- Veröffentlicht 04.05.2026 12:38:28
- Zuletzt bearbeitet 11.05.2026 12:27:11
Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quant...
CVE-2026-42249
- EPSS 0.63%
- Veröffentlicht 29.04.2026 12:16:19
- Zuletzt bearbeitet 18.05.2026 18:23:25
Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the application constructs local file paths using values derive...
CVE-2026-42248
- EPSS 0.38%
- Veröffentlicht 29.04.2026 12:16:18
- Zuletzt bearbeitet 18.05.2026 18:22:55
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unconditionally returns success so no digital signature...