CVE-2026-15685High· 7.5▾ Abyssal0dayOllama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not require…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 41.3 · likelihood 0.1 · exploitation 25
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 16.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.7%
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the downloadBlob function. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated array. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-27277.
ollama <= 0.7.1-NARefer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86289Medium· 4.3A vulnerability was found in Ollama up to 0.31.1
CVE-2025-15514High· 7.5Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality
CVE-2024-28224High· 8.8Ollama DNS rebinding vulnerability
CVE-2024-8063High· 7.5Ollama Divide by Zero Vulnerability
CVE-2025-63389CriticalOllama Platform has missing authentication enabling attackers to perform model management operations
CVE-2026-7020Medium· 5.6Ollama is Vulnerable to Path Traversal