---
id: CVE-2026-15685
aliases:
  - PYSEC-2026-3450
title: >-
  Ollama downloadBlob Improper Validation of Array Index Denial-of-Service
  Vulnerability. This vulnerability allows remote attackers to cre…
summary: >-
  Ollama downloadBlob Improper Validation of Array Index Denial-of-Service
  Vulnerability. This vulnerability allows remote attackers to create a
  denial-of-service condition on affected installations of Ollama.
  Authentication is not require…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: ollama
product: ollama
ecosystem: pip
affected:
  - ollama <= 0.7.1-NA
published: '2026-07-13'
updated: '2026-07-15'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2026-3450'
references:
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-26-403/'
tags:
  - osv
  - pip
epss: 0.00715
epssPercentile: 0.51668
zeroDay: true
ingestedAt: '2026-07-16T18:59:42.108Z'
---

## Overview

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the downloadBlob function. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated array. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-27277.

## Affected packages

- `ollama <= 0.7.1-NA`

## Remediation

Refer to the advisory for the patched release.
