Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ollama HIGH 7.5
CVE-2026-15685

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial…

Mitigation only
Fix from $1,950 2026-07-13
Ollama HIGH 7.5
CVE-2026-5757

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the serve…

Fix: after 0.13.5
Fix from $1,950 2026-06-26
Ollama CRITICAL 9.1
CVE-2026-7482

Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied…

Fix: 0.17.1+
Fix from $2,300 2026-05-04
Ollama CRITICAL 9.8
CVE-2026-42249

Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP respon…

Fix: after 0.17.5
Fix from $2,300 2026-04-29
Ollama CRITICAL 9.8
CVE-2026-42248

Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows impl…

Fix: after 0.17.5
Fix from $2,300 2026-04-29
Ollama HIGH 7.5
CVE-2025-66959

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder

No fix yet
Fix from $1,950 2026-01-21
Ollama HIGH 7.5
CVE-2025-66960

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string …

No fix yet
Fix from $1,950 2026-01-21
Ollama HIGH 7.5
CVE-2025-15514

Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functiona…

Fix: after 0.13.5
Fix from $1,950 2026-01-12
Ollama CRITICAL 9.8
CVE-2025-63389

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exp…

Fix: after 0.12.3
Fix from $2,300 2025-12-18
Ollama MEDIUM 6.6
CVE-2025-44779

An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.

Mitigation only
Fix from $1,600 2025-08-07
Ollama MEDIUM 6.9
CVE-2025-51471EPSS 13%

Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass ac…

Patch available
Fix from $1,600 2025-07-22
Ollama HIGH 7.5
CVE-2025-1975

A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest con…

No fix yet
Fix from $1,950 2025-05-16
Ollama HIGH 7.5
CVE-2025-0312

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on …

Fix: after 0.3.14
Fix from $1,950 2025-03-20
Ollama HIGH 7.5
CVE-2025-0315

A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create …

Fix: after 0.3.14
Fix from $1,950 2025-03-20
Ollama HIGH 7.5
CVE-2025-0317EPSS 14%

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. Th…

Fix: after 0.3.14
Fix from $1,950 2025-03-20
Ollama HIGH 7.5
CVE-2024-8063

A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `b…

No fix yet
Fix from $1,950 2025-03-20
Ollama HIGH 7.5
CVE-2024-12055

A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama …

Fix: after 0.3.14
Fix from $1,950 2025-03-20
Ollama HIGH 7.5
CVE-2024-39722

An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/pus…

Fix: 0.1.46+
Fix from $1,950 2024-10-31
Ollama HIGH 8.2
CVE-2024-39720

An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starti…

Fix: 0.1.46+
Fix from $1,950 2024-10-31
Ollama HIGH 7.5
CVE-2024-39719

An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path …

Fix: after 0.3.14
Fix from $1,950 2024-10-31
Ollama HIGH 7.5
CVE-2024-39721

An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter…

Fix: 0.1.34+
Fix from $1,950 2024-10-31
Ollama HIGH 7.5
CVE-2024-45436

extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.

Fix: 0.1.47+
Fix from $1,950 2024-08-29
Ollama HIGH 8.8
CVE-2024-37032EPSS 90%

Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the Test…

Fix: 0.1.34+
Fix from $1,950 2024-05-31
Ollama MEDIUM 6.6
CVE-2024-28224

Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized us…

Fix: 0.1.29+
Fix from $1,600 2024-04-08