CVE Tools

Github.com/ollama/ollama

14 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Github.com/ollama/ollama, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Github.com/ollama/ollama CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Github.com/ollama/ollama CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-010
2025-020
2025-036
2025-040
2025-051
2025-060
2025-071
2025-081
2025-090
2025-100
2025-110
2025-121
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical17%
  • High1071%
  • Medium321%

Latest CVEs

The 14 most recently published vulnerabilities affecting Github.com/ollama/ollama.

  1. CVE-2025-63389A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring au...9.8
  2. CVE-2025-44779An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.6.6
  3. CVE-2025-51471Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a W...6.9
  4. CVE-2025-1975Improper Validation of Array Index in ollama/ollama7.5
  5. CVE-2024-8063Divide by Zero in ollama/ollama7.5
  6. CVE-2025-0312NULL Pointer Dereference in ollama/ollama7.5
  7. CVE-2024-12886Out-Of-Memory (OOM) Vulnerability in ollama/ollama7.5
  8. CVE-2025-0317Divide By Zero in ollama/ollama7.5
  9. CVE-2025-0315Allocation of Resources Without Limits or Throttling in ollama/ollama7.5
  10. CVE-2024-12055DoS using malicious gguf model file in ollama/ollama7.5
  11. CVE-2024-39720An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leverag...8.2
  12. CVE-2024-45436extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.7.5
  13. CVE-2024-37032Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 he...8.8
  14. CVE-2024-28224Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a mo...6.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store