Skip to content
OllamaGHSA-8hqg-whrw-pv92

Ollama does not validate the format of the digest (sha256 with 64 hex digits)

MediumCVE-2024-37032 · Published May 31, 2024 · updated Sep 10, 2026

Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial `../` substring.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/ollama/ollama
Go
< 0.1.340.1.34
Details and references

More Ollama advisories

All Ollama
Advisory
Ollama Divide by Zero Vulnerability
High7.5Mar 20, 2025
Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP
High7.5Mar 20, 2025
Ollama Allows Out-of-Bounds Read
High7.5Mar 20, 2025
Ollama Out-of-bounds Read
High8.2Oct 31, 2024
Ollama can extract members of a ZIP archive outside of the parent directory
High7.5Aug 29, 2024
Ollama DNS rebinding vulnerability
High8.8Apr 8, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.