Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-15685 Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial… Ollama Mitigation only Fix from $1,9502026-07-13 HIGH 7.5 CVE-2026-5757 Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the serve… Ollama after 0.13.5 Fix from $1,9502026-06-26 CRITICAL 9.1 CVE-2026-7482 Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied… Ollama 0.17.1+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42249 Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP respon… Ollama after 0.17.5 Fix from $2,3002026-04-29 CRITICAL 9.8 CVE-2026-42248 Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows impl… Ollama after 0.17.5 Fix from $2,3002026-04-29 HIGH 7.5 CVE-2025-66959 An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder Ollama No fix yet Fix from $1,9502026-01-21 HIGH 7.5 CVE-2025-66960 An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string … Ollama No fix yet Fix from $1,9502026-01-21 HIGH 7.5 CVE-2025-15514 Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functiona… Ollama after 0.13.5 Fix from $1,9502026-01-12 CRITICAL 9.8 CVE-2025-63389 A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exp… Ollama after 0.12.3 Fix from $2,3002025-12-18 MEDIUM 6.6 CVE-2025-44779 An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull. Ollama Mitigation only Fix from $1,6002025-08-07 MEDIUM 6.9 CVE-2025-51471EPSS 13% Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass ac… Ollama Patch available Fix from $1,6002025-07-22 HIGH 7.5 CVE-2025-1975 A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest con… Ollama No fix yet Fix from $1,9502025-05-16 HIGH 7.5 CVE-2025-0312 A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on … Ollama after 0.3.14 Fix from $1,9502025-03-20 HIGH 7.5 CVE-2025-0315 A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create … Ollama after 0.3.14 Fix from $1,9502025-03-20 HIGH 7.5 CVE-2025-0317EPSS 14% A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. Th… Ollama after 0.3.14 Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-8063 A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `b… Ollama No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-12055 A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama … Ollama after 0.3.14 Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-39722 An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/pus… Ollama 0.1.46+ Fix from $1,9502024-10-31 HIGH 8.2 CVE-2024-39720 An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starti… Ollama 0.1.46+ Fix from $1,9502024-10-31 HIGH 7.5 CVE-2024-39719 An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path … Ollama after 0.3.14 Fix from $1,9502024-10-31 HIGH 7.5 CVE-2024-39721 An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter… Ollama 0.1.34+ Fix from $1,9502024-10-31 HIGH 7.5 CVE-2024-45436 extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory. Ollama 0.1.47+ Fix from $1,9502024-08-29 HIGH 8.8 CVE-2024-37032EPSS 90% Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the Test… Ollama 0.1.34+ Fix from $1,9502024-05-31 MEDIUM 6.6 CVE-2024-28224 Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized us… Ollama 0.1.29+ Fix from $1,6002024-04-08