Ollama
9 known vulnerabilities
Top Products
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote
Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to
Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint
Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of at
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike othe
A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagege
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function rea
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder
Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal mod
Frequently Asked Questions
How many CVEs affect Ollama?
Ollama has 9 CVE records in our database, including 3 critical and 5 high severity vulnerabilities.
What are the most severe Ollama vulnerabilities?
Ollama has 3 critical severity (CVSS 9.0+) and 5 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Ollama vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Ollama products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Ollama Vulnerabilities
CyberStrike scans your infrastructure for Ollama vulnerabilities and provides real-time remediation guidance.
Get Started