OllamaGHSA-fccc-8m69-8r78
Ollama Allocation of Resources Without Limits or Throttling vulnerability
High7.5CVE-2025-0315 · Published Mar 20, 2025 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/ollama/ollama Go | <= 0.3.14 | No fix yet |
Details and references
A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate unlimited memory, leading to a Denial of Service (DoS) attack.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-770
- Also known as
- CVE-2025-0315, GO-2025-3557
More Ollama advisories
All Ollama| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | Ollama Allows Out-of-Bounds Read CVE-2024-12055High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP CVE-2024-12886High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Ollama Divide by Zero Vulnerability CVE-2024-8063High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Ollama Divide By Zero vulnerability CVE-2025-0317High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Ollama Denial of Service (DoS) via Null Pointer Dereference CVE-2025-0312High7.5no fix yet | High7.5 | No fix yet |
| May 162025 | Ollama Server Vulnerable to Denial of Service (DoS) Attack CVE-2025-1975High7.5no fix yet | High7.5 | No fix yet |