Bounties
Partners
Community
Info
ollama / ollama
Project repository
Get up and running with Llama 3.2, Mistral, Gemma 2, and other large language models.
Submit a report
FIRST INTERACTION
WITHIN
5 DAYS
REVIEW
WITHIN
5 DAYS
FIX
WITHIN
N/A DAYS
SSRF via unvalidated Content-Location header in chunksums endpoint (client2 regi...
May 10th 2026
cerq99
•
duplicate
Medium
SSRF via Arbitrary Registry Host in Model Pull Allows Internal Network Access
May 10th 2026
l69d
•
duplicate
High
Blind SSRF via Content-Location Header in Registry Pull (chunksums flow)
May 10th 2026
syaixlabs-tech
•
duplicate
Medium
Ollama macOS Auto-Updater Zip Slip in verifyDownload() (CWE-22)
May 8th 2026
theluckystrike
•
duplicate
High
macOS updater ZIP slip allows arbitrary file write outside /Applications/Ollama....
May 8th 2026
s1ko
•
duplicate
High
SSRF via /api/pull with user-controlled registry host and insecure flag
May 10th 2026
jd-admrl-ai
•
duplicate
High
Unauthenticated SSRF-to-secret-exfil chain in /api/pull via attacker-controlled...
Apr 24th 2026
mirr2
•
self closed
Unauthenticated SSRF in /api/pull via attacker-controlled registry host
Apr 23rd 2026
01data-ai
•
duplicate
High
SSRF via Unauthenticated /api/pull Endpoint — Attacker-Controlled URL in Model N...
Apr 23rd 2026
sermikr0
•
duplicate
High
Unbounded Tensor Dimensions Allocation Causes OOM Crash
Apr 13th 2026
elromevedelelyon
•
duplicate
None
Non-Blind SSRF via Deprecated `insecure` Parameter in /api/pull — Full Response...
Apr 13th 2026
chw81
•
duplicate
High
No authentication on destructive API endpoints when bound to 0.0.0.0 allows unau...
Apr 12th 2026
snakeyworm
•
duplicate
Critical
DNS rebinding bypass via .internal/.local TLD in allowedHostsMiddleware allows u...
Apr 12th 2026
snakeyworm
•
duplicate
Critical
Path traversal via unvalidated digest in transfer download path enables arbitrar...
Apr 12th 2026
snakeyworm
•
self closed
Path traversal via unvalidated digest in transfer download path enables arbitrar...
Apr 12th 2026
snakeyworm
•
self closed
Path traversal via unvalidated digest in transfer download path enables arbitrar...
Apr 12th 2026
snakeyworm
•
self closed
Path traversal via unvalidated digest in transfer download path enables arbitrar...
Apr 12th 2026
snakeyworm
•
self closed
Multiple OOM/Panic DoS in GGUF Parser via Unbounded Memory Allocations
Apr 11th 2026
skillwager
•
duplicate
High
Multiple OOM/Panic DoS in GGUF Parser via Unbounded Allocations (gguf.go)
Apr 13th 2026
skillwager
•
duplicate
Medium
No authentication on destructive API endpoints when bound to 0.0.0.0 allows unau...
Apr 12th 2026
wormysnake
•
duplicate
Critical
DNS rebinding bypass via .internal/.local TLD in allowedHostsMiddleware allows u...
Apr 12th 2026
wormysnake
•
duplicate
Critical
Improper Input Validation on Safetensor leading to Remote DoS
Apr 5th 2026
river-li
•
self closed
GGUF Parser OOM via Unbounded String Allocation
Apr 11th 2026
river-li
•
duplicate
High
Unbounded memory allocation in GGUF parser crashes server via crafted model file
Apr 11th 2026
ayushparkara
•
duplicate
High
SSRF via /api/pull with user-controlled registry host — no IP validation
May 10th 2026
lihfdgjr
•
duplicate
Medium
Malformed WWW-Authenticate header causes unhandled panic (DoS) in /api/pull and...
Mar 29th 2026
flamki
•
duplicate
High
Improper GGUF File Validation Leads to Persistent DoS
Mar 26th 2026
jaquelinedops
•
duplicate
Critical
Remote DoS via String Length Overflow in Go GGUF Parser
Mar 26th 2026
flex0geek
•
duplicate
High
Remote DoS via Array Count Overflow in Go GGUF Parser
Mar 26th 2026
flex0geek
•
duplicate
High
Remote DoS via SIGFPE in GGUF C Parser (Division by Zero)
Mar 26th 2026
flex0geek
•
duplicate
High
Remote DoS via Unrecovered Goroutine Panic in `/api/create`
Mar 26th 2026
flex0geek
•
duplicate
High
DNS Rebinding Attack via Overly Permissive .local/.internal TLD Allowlist in all...
Apr 12th 2026
rohanmulay1
•
duplicate
High
DoS via integer overflow in readGGUFString (GGUF parser)
Mar 26th 2026
radikhoroshev
•
duplicate
High
Unvalidated Allocation Size in GGUF Parser Causes OOM Denial of Service
Apr 11th 2026
nhomyk
•
duplicate
High
Denial of Service via Unbounded Memory Allocation in GGUF String Parsing
Mar 19th 2026
twsky100
•
duplicate
High
DNS Rebinding Bypass of Host Validation Allows Cross-Origin API Access
Mar 19th 2026
twsky100
•
duplicate
High
DNS Rebinding bypasses allowedHostsMiddleware via .local/.internal TLD wildcard
Mar 19th 2026
eistee82
•
duplicate
High
Show more...
CRITICAL
$1500
HIGH
$750
MEDIUM
$125
LOW
$20