OllamaGHSA-wrh5-cmwx-q2qr
Ollama Server Vulnerable to Denial of Service (DoS) Attack
High7.5CVE-2025-1975 · Published May 16, 2025 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/ollama/ollama Go | <= 0.5.11 | No fix yet |
Details and references
A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the /api/pull endpoint, which can lead to a server crash.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-129
- Also known as
- CVE-2025-1975, GO-2025-3695
More Ollama advisories
All Ollama| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | Ollama Divide By Zero vulnerability CVE-2025-0317High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Ollama Allocation of Resources Without Limits or Throttling vulnerability CVE-2025-0315High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Ollama Denial of Service (DoS) via Null Pointer Dereference CVE-2025-0312High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Ollama Divide by Zero Vulnerability CVE-2024-8063High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP CVE-2024-12886High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Ollama Allows Out-of-Bounds Read CVE-2024-12055High7.5no fix yet | High7.5 | No fix yet |