CVE-2024-28224High· 8.8▾ TwilightOllama DNS rebinding vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).
github.com/ollama/ollama < 0.1.29Upgrade to a patched release:
github.com/ollama/ollama 0.1.29Connected by shared product, vendor, weakness, or advisory.
CVE-2024-8063High· 7.5Ollama Divide by Zero Vulnerability
CVE-2025-63389CriticalOllama Platform has missing authentication enabling attackers to perform model management operations
CVE-2026-7020Medium· 5.6Ollama is Vulnerable to Path Traversal
CVE-2026-7482Critical· 9.1Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader
CVE-2026-15685High· 7.5Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…
CVE-2025-15514High· 7.5Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality