Ollama is a widely adopted tool for running large language models locally, and despite a narrow product portfolio, its positioning as a commonly deployed inference engine has made it more prominent than typical in the vulnerability landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrating in path traversal, improper input validation, out-of-bounds reads, and divide-by-zero conditions that reflect both the complexity of model-loading and inference code and the security implications of accepting untrusted model files and user input. The single-product focus means that fixes must be applied uniformly across deployments, and the recurrence of path traversal and integrity-check weaknesses highlights the risk of local file exposure and model poisoning in environments where models are sourced from untrusted or third-party repositories. Defenders should monitor this vendor's releases closely given the concentration of critical findings and the breadth of deployment in development, research, and production environments; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ollama over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-37032HIGH Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as | May 31, 2024 | 8.8 | 89 | NO | YES |
CVE-2026-7482CRITICAL Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declare | May 4, 2026 | 9.1 | 44 | NO | NO |
CVE-2026-42249CRITICAL Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading up | Apr 29, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-42248CRITICAL Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verifi | Apr 29, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-5757HIGH Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially le | Jun 26, 2026 | 7.5 | 37 | NO | NO |
CVE-2025-63389CRITICAL A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints wit | Dec 18, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-15685HIGH Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affect | Jul 13, 2026 | 7.5 | 33 | NO | NO |
CVE-2024-39719HIGH An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist, | Oct 31, 2024 | 7.5 | 28 | NO | NO |
CVE-2025-0317HIGH A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by ze | Mar 20, 2025 | 7.5 | 27 | NO | NO |
CVE-2025-66959HIGH An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder | Jan 21, 2026 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ollama.
Media articles that mention a CVE ID that affects a product developed by Ollama — matched by CVE ID, not by vendor name.