VYPR

rpm package

opensuse/ollama&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/ollama&distro=openSUSE%20Tumbleweed

Vulnerabilities (2)

  • CVE-2026-7482CriMay 4, 2026
    affected < 0.33.1-1.1fixed 0.33.1-1.1

    Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quantization in fs/ggml/gguf.go and

  • CVE-2025-47911MedFeb 5, 2026
    affected < 0.12.6-1.1fixed 0.12.6-1.1

    The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.