Skip to content
OllamaGHSA-p2wh-w96x-w232

Ollama Denial of Service (DoS) via Null Pointer Dereference

High7.5CVE-2025-0312 · Published Mar 20, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/ollama/ollama
Go
<= 0.3.14No fix yet
Details and references

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama server, can cause a crash due to an unchecked null pointer dereference. This can lead to a Denial of Service (DoS) attack via remote network.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-476
Also known as
CVE-2025-0312, GO-2025-3582

More Ollama advisories

All Ollama
DateAdvisory
Mar 202025Ollama Allows Out-of-Bounds Read
CVE-2024-12055High7.5no fix yet
Mar 202025Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP
CVE-2024-12886High7.5no fix yet
Mar 202025Ollama Divide by Zero Vulnerability
CVE-2024-8063High7.5no fix yet
Mar 202025Ollama Divide By Zero vulnerability
CVE-2025-0317High7.5no fix yet
Mar 202025Ollama Allocation of Resources Without Limits or Throttling vulnerability
CVE-2025-0315High7.5no fix yet
May 162025Ollama Server Vulnerable to Denial of Service (DoS) Attack
CVE-2025-1975High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.