Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-15685
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial…
Ollama
Mitigation only
HIGH 7.5
CVE-2026-5757
Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the serve…
Ollama
after 0.13.5
CRITICAL 9.1
CVE-2026-7482
Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied…
Ollama
0.17.1+
CRITICAL 9.8
CVE-2026-42249
Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP respon…
Ollama
after 0.17.5
CRITICAL 9.8
CVE-2026-42248
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows impl…
Ollama
after 0.17.5
HIGH 7.5
CVE-2025-66959
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder
Ollama
No fix yet
HIGH 7.5
CVE-2025-66960
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string …
Ollama
No fix yet
HIGH 7.5
CVE-2025-15514
Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functiona…
Ollama
after 0.13.5
CRITICAL 9.8
CVE-2025-63389
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exp…
Ollama
after 0.12.3
MEDIUM 6.6
CVE-2025-44779
An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.
Ollama
Mitigation only
MEDIUM 6.9
CVE-2025-51471EPSS 13%
Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass ac…
Ollama
Patch available
HIGH 7.5
CVE-2025-1975
A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest con…
Ollama
No fix yet
HIGH 7.5
CVE-2025-0312
A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on …
Ollama
after 0.3.14
HIGH 7.5
CVE-2025-0315
A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create …
Ollama
after 0.3.14
HIGH 7.5
CVE-2025-0317EPSS 14%
A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. Th…
Ollama
after 0.3.14
HIGH 7.5
CVE-2024-8063
A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `b…
Ollama
No fix yet
HIGH 7.5
CVE-2024-12055
A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama …
Ollama
after 0.3.14
HIGH 7.5
CVE-2024-39722
An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/pus…
Ollama
0.1.46+
HIGH 8.2
CVE-2024-39720
An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starti…
Ollama
0.1.46+
HIGH 7.5
CVE-2024-39719
An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path …
Ollama
after 0.3.14
HIGH 7.5
CVE-2024-39721
An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter…
Ollama
0.1.34+
HIGH 7.5
CVE-2024-45436
extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.
Ollama
0.1.47+
HIGH 8.8
CVE-2024-37032EPSS 90%
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the Test…
Ollama
0.1.34+
MEDIUM 6.6
CVE-2024-28224
Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized us…
Ollama
0.1.29+