Browse all 15 CVE security advisories affecting ollama. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Ollama serves as a platform for running and managing large language models locally, enabling developers to deploy AI models without cloud dependencies. Historically, the project has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, with 11 CVEs documented to date. Security concerns often stem from improper input validation and insecure default configurations. While no major public security incidents have been widely reported, the accumulation of CVEs indicates ongoing challenges in secure development practices. Users should implement network segmentation and regular updates to mitigate risks associated with local model deployments.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-1975 | Improper Validation of Array Index in ollama/ollama — ollama/ollama CWE-129 | 7.5AI | High AI | 2025-05-16 |
| CVE-2024-8063 | Divide by Zero in ollama/ollama — ollama/ollama CWE-369 | 7.5 | - | 2025-03-20 |
| CVE-2025-0312 | NULL Pointer Dereference in ollama/ollama — ollama/ollama CWE-476 | 6.5 | - | 2025-03-20 |
| CVE-2024-12886 | Out-Of-Memory (OOM) Vulnerability in ollama/ollama — ollama/ollama CWE-409 | 7.5 | - | 2025-03-20 |
| CVE-2025-0317 | Divide By Zero in ollama/ollama — ollama/ollama CWE-369 | 6.5 | - | 2025-03-20 |
| CVE-2025-0315 | Allocation of Resources Without Limits or Throttling in ollama/ollama — ollama/ollama CWE-770 | 6.5 | - | 2025-03-20 |
| CVE-2024-12055 | DoS using malicious gguf model file in ollama/ollama — ollama/ollama CWE-125 | 6.5 | - | 2025-03-20 |
This page lists every published CVE security advisory associated with ollama. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.