Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ollama

First CVE: Apr 8, 2024Active for: 2 yearsTotal CVEs: 25
63.0
VTI Score
TOP TARGET

Ollama is a widely adopted tool for running large language models locally, and despite a narrow product portfolio, its positioning as a commonly deployed inference engine has made it more prominent than typical in the vulnerability landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrating in path traversal, improper input validation, out-of-bounds reads, and divide-by-zero conditions that reflect both the complexity of model-loading and inference code and the security implications of accepting untrusted model files and user input. The single-product focus means that fixes must be applied uniformly across deployments, and the recurrence of path traversal and integrity-check weaknesses highlights the risk of local file exposure and model poisoning in environments where models are sourced from untrusted or third-party repositories. Defenders should monitor this vendor's releases closely given the concentration of critical findings and the breadth of deployment in development, research, and production environments; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
8.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ollama over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2024
2 years ago
Most Recent CVE
Jul 13, 2026
11 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-37032HIGH
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as
May 31, 20248.889NOYES
CVE-2026-7482CRITICAL
Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declare
May 4, 20269.144NONO
CVE-2026-42249CRITICAL
Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading up
Apr 29, 20269.839NONO
CVE-2026-42248CRITICAL
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verifi
Apr 29, 20269.839NONO
CVE-2026-5757HIGH
Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially le
Jun 26, 20267.537NONO
CVE-2025-63389CRITICAL
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints wit
Dec 18, 20259.834NONO
CVE-2026-15685HIGH
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affect
Jul 13, 20267.533NONO
CVE-2024-39719HIGH
An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist,
Oct 31, 20247.528NONO
CVE-2025-0317HIGH
A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by ze
Mar 20, 20257.527NONO
CVE-2025-66959HIGH
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder
Jan 21, 20267.526NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
12%
68%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (8.0%)
Network23 (92.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (92.0%)
High2 (8.0%)
Unknown0 (0.0%)
User Interaction
None23 (92.0%)
Unknown0 (0.0%)
Required2 (8.0%)
Privileges Required
Low2 (8.0%)
High0 (0.0%)
None23 (92.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.0% of CVEs· 98th percentile
Nuclei
1 CVE
4.0% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ollama.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ollama — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ollama's Products

View all 8 CNAs →

Top CWEs