Ollama

Ollama

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.71%
  • Veröffentlicht 12.01.2026 23:03:52
  • Zuletzt bearbeitet 17.08.2026 19:16:23

Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data via the /api/chat endpoint, the application fails to ...

  • EPSS 0.72%
  • Veröffentlicht 18.12.2025 00:00:00
  • Zuletzt bearbeitet 22.01.2026 18:16:43

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform un...

  • EPSS 0.18%
  • Veröffentlicht 07.08.2025 00:00:00
  • Zuletzt bearbeitet 14.08.2025 20:00:57

An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.

Exploit
  • EPSS 13.19%
  • Veröffentlicht 22.07.2025 00:00:00
  • Zuletzt bearbeitet 17.10.2025 18:15:36

Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endp...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 16.05.2025 08:25:57
  • Zuletzt bearbeitet 24.06.2025 16:40:44

A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloadin...

Exploit
  • EPSS 0.62%
  • Veröffentlicht 20.03.2025 10:10:56
  • Zuletzt bearbeitet 13.05.2025 13:28:05

A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a denial of service (DoS) condition when the server pr...

Exploit
  • EPSS 0.62%
  • Veröffentlicht 20.03.2025 10:10:53
  • Zuletzt bearbeitet 28.03.2025 14:11:12

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama server, can cause a crash due to an unchecked null pointer dereference. This can lead to a...

  • EPSS 0.71%
  • Veröffentlicht 20.03.2025 10:10:28
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered when a malicious API server responds with a gzip bomb HTTP response, leading to the `ollama` server crashing. The vulnerability is ...

Exploit
  • EPSS 14.03%
  • Veröffentlicht 20.03.2025 10:10:02
  • Zuletzt bearbeitet 02.04.2025 16:07:20

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the ggufPadding function, causing the server to crash and ...

Exploit
  • EPSS 0.64%
  • Veröffentlicht 20.03.2025 10:09:48
  • Zuletzt bearbeitet 02.04.2025 16:02:38

A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate unlimited memory, leading to a Denial of Service (DoS) atta...