VulnSea

Ollama has 8 CVEs on record between 2024 and 2026. 2 were published in the last 90 days. The median CVSS is 7.5 (high), with 2 rated critical. None have a confirmed exploitation report. Most affected products: github.com/ollama/ollama (5), Ollama (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
—
Last 90 days
2 prev 2

Weakness classes

Products

  • github.com/ollama/ollama 5
  • Ollama 3
8
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

Ollama vulnerabilities

CVEs affecting Ollama, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-65315High· 7.5
2mo ago

Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parser

Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields…

▾ TwilightOllama · OllamaEPSS 0.81%via CVEORG
CVE-2026-15685High· 7.50day
2mo ago

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not require…

▾ Abyssalollama · ollamaEPSS 0.71%via OSV
CVE-2026-7482Critical· 9.1PoC
4mo ago

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

▾ Abyssalollama · github.com/ollama/ollamaEPSS 2.2%via OSV
CVE-2026-7020Medium· 5.6PoC
5mo ago

Ollama is Vulnerable to Path Traversal

Ollama is Vulnerable to Path Traversal

▾ Twilightollama · github.com/ollama/ollamaEPSS 0.91%via OSV
CVE-2025-15514High· 7.5PoC
8mo ago

Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality

Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data via the /api/chat endpoint, the applicat…

▾ Midnightollama · ollamaEPSS 0.78%via NVD
CVE-2025-63389Critical
9mo ago

Ollama Platform has missing authentication enabling attackers to perform model management operations

Ollama Platform has missing authentication enabling attackers to perform model management operations

▾ Midnightollama · github.com/ollama/ollamaEPSS 0.71%via OSV
CVE-2024-8063High· 7.5
1y ago

Ollama Divide by Zero Vulnerability

Ollama Divide by Zero Vulnerability

▾ Twilightollama · github.com/ollama/ollamaEPSS 0.63%via OSV
CVE-2024-28224High· 8.8
2y ago

Ollama DNS rebinding vulnerability

Ollama DNS rebinding vulnerability

▾ Twilightollama · github.com/ollama/ollamaEPSS 0.33%via OSV
Ollama vulnerabilities (CVEs) · VulnSea