Skip to content
OllamaGHSA-wrh5-cmwx-q2qr

Ollama Server Vulnerable to Denial of Service (DoS) Attack

High7.5CVE-2025-1975 · Published May 16, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/ollama/ollama
Go
<= 0.5.11No fix yet
Details and references

A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the /api/pull endpoint, which can lead to a server crash.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-129
Also known as
CVE-2025-1975, GO-2025-3695

More Ollama advisories

All Ollama
DateAdvisory
Mar 202025Ollama Divide By Zero vulnerability
CVE-2025-0317High7.5no fix yet
Mar 202025Ollama Allocation of Resources Without Limits or Throttling vulnerability
CVE-2025-0315High7.5no fix yet
Mar 202025Ollama Denial of Service (DoS) via Null Pointer Dereference
CVE-2025-0312High7.5no fix yet
Mar 202025Ollama Divide by Zero Vulnerability
CVE-2024-8063High7.5no fix yet
Mar 202025Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP
CVE-2024-12886High7.5no fix yet
Mar 202025Ollama Allows Out-of-Bounds Read
CVE-2024-12055High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.