Skip to content
OllamaGHSA-5jx5-hqx5-2vrj

Ollama DNS rebinding vulnerability

High8.8CVE-2024-28224 · Published Apr 8, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/ollama/ollama
Go
< 0.1.290.1.29
Details and references

Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-290, CWE-346, CWE-350
Also known as
CVE-2024-28224, GO-2024-2699

More Ollama advisories

All Ollama
DateAdvisory
May 312024Ollama does not validate the format of the digest (sha256 with 64 hex digits)
CVE-2024-37032Mediumfixed in 0.1.34
Aug 292024Ollama can extract members of a ZIP archive outside of the parent directory
CVE-2024-45436High7.5fixed in 0.1.47
Oct 312024Ollama Out-of-bounds Read
CVE-2024-39720High8.2fixed in 0.1.46
Mar 202025Ollama Allows Out-of-Bounds Read
CVE-2024-12055High7.5no fix yet
Mar 202025Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP
CVE-2024-12886High7.5no fix yet
Mar 202025Ollama Divide by Zero Vulnerability
CVE-2024-8063High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.