VYPR

Ollama

by Ollama

Source repositories

CVEs (29)

  • CVE-2025-44779MedAug 7, 2025
    risk 0.43cvss 6.6epss 0.00

    An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.

  • CVE-2024-39722HigOct 31, 2024
    risk 0.42cvss 7.5epss 0.04

    An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/push route.

  • CVE-2024-39721HigOct 31, 2024
    risk 0.42cvss 7.5epss 0.03

    An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be set to /dev/random, which is blocking, causing the goroutine to run infinitely (even after the HTTP…

  • CVE-2024-45436HigAug 29, 2024
    risk 0.42cvss 7.5epss 0.03

    extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.

  • CVE-2026-5530MedApr 5, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was…

  • CVE-2025-51471MedJul 22, 2025
    risk 0.38cvss 6.9epss 0.13

    Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint.

  • CVE-2024-28224MedApr 8, 2024
    risk 0.36cvss 6.6epss 0.00

    Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).

  • CVE-2026-7020LowApr 26, 2026
    risk 0.17cvss 3.7epss 0.01

    A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path traversal. The attack may be…

  • CVE-2026-65315HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string lengths, tensor dimension…

Page 2 of 2