CVE-2026-7020
- EPSS 0.91%
- Veröffentlicht 26.04.2026 05:16:02
- Zuletzt bearbeitet 06.05.2026 06:16:08
A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path tra...
CVE-2026-5530
- EPSS 0.3%
- Veröffentlicht 05.04.2026 00:30:13
- Zuletzt bearbeitet 24.07.2026 09:10:00
A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remo...
CVE-2025-66959
- EPSS 4.63%
- Veröffentlicht 21.01.2026 00:00:00
- Zuletzt bearbeitet 02.02.2026 17:27:47
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder
CVE-2025-66960
- EPSS 0.37%
- Veröffentlicht 21.01.2026 00:00:00
- Zuletzt bearbeitet 02.02.2026 17:27:26
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata
CVE-2025-15514
- EPSS 0.71%
- Veröffentlicht 12.01.2026 23:03:52
- Zuletzt bearbeitet 17.08.2026 19:16:23
Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data via the /api/chat endpoint, the application fails to ...
CVE-2025-63389
- EPSS 0.72%
- Veröffentlicht 18.12.2025 00:00:00
- Zuletzt bearbeitet 22.01.2026 18:16:43
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform un...
CVE-2025-44779
- EPSS 0.18%
- Veröffentlicht 07.08.2025 00:00:00
- Zuletzt bearbeitet 14.08.2025 20:00:57
An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.
CVE-2025-51471
- EPSS 13.19%
- Veröffentlicht 22.07.2025 00:00:00
- Zuletzt bearbeitet 17.10.2025 18:15:36
Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endp...
CVE-2025-1975
- EPSS 0.5%
- Veröffentlicht 16.05.2025 08:25:57
- Zuletzt bearbeitet 24.06.2025 16:40:44
A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloadin...
CVE-2024-8063
- EPSS 0.62%
- Veröffentlicht 20.03.2025 10:10:56
- Zuletzt bearbeitet 13.05.2025 13:28:05
A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a denial of service (DoS) condition when the server pr...