ollama has 7 CVEs on record between 2024 and 2026. 1 was published in the last 90 days. The median CVSS is 7.5 (high), with 2 rated critical. None have a confirmed exploitation report. Most affected products: github.com/ollama/ollama (5), ollama (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 2
Weakness classes
Products
- github.com/ollama/ollama 5
- ollama 2
Worst active — by depth score
CVE-2026-15685High· 7.5Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…66CVE-2026-7482Critical· 9.1Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader62CVE-2025-15514High· 7.5Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality53CVE-2025-63389CriticalOllama Platform has missing authentication enabling attackers to perform model management operations52CVE-2024-28224High· 8.8Ollama DNS rebinding vulnerability48
ollama vulnerabilities
CVEs affecting ollama, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-15685High· 7.50dayOllama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not require…
CVE-2026-7482Critical· 9.1PoCOllama contains a heap out-of-bounds read vulnerability in the GGUF model loader
Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader
CVE-2026-7020Medium· 5.6PoCOllama is Vulnerable to Path Traversal
Ollama is Vulnerable to Path Traversal
CVE-2025-15514High· 7.5PoCOllama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality
Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data via the /api/chat endpoint, the applicat…
CVE-2025-63389CriticalOllama Platform has missing authentication enabling attackers to perform model management operations
Ollama Platform has missing authentication enabling attackers to perform model management operations
CVE-2024-8063High· 7.5Ollama Divide by Zero Vulnerability
Ollama Divide by Zero Vulnerability
CVE-2024-28224High· 8.8Ollama DNS rebinding vulnerability
Ollama DNS rebinding vulnerability