Bounties
Partners
Community
Info
ollama / ollama
Project repository
Get up and running with Llama 3.2, Mistral, Gemma 2, and other large language models.
Submit a report
FIRST INTERACTION
WITHIN
N/A DAYS
REVIEW
WITHIN
14 DAYS
FIX
WITHIN
N/A DAYS
Malformed WWW-Authenticate header causes unhandled panic (DoS) in /api/pull and...
Mar 29th 2026
flamki
•
duplicate
High
Improper GGUF File Validation Leads to Persistent DoS
Mar 26th 2026
jaquelinedops
•
duplicate
Critical
Remote DoS via String Length Overflow in Go GGUF Parser
Mar 26th 2026
flex0geek
•
duplicate
High
Remote DoS via Array Count Overflow in Go GGUF Parser
Mar 26th 2026
flex0geek
•
duplicate
High
Remote DoS via SIGFPE in GGUF C Parser (Division by Zero)
Mar 26th 2026
flex0geek
•
duplicate
High
Remote DoS via Unrecovered Goroutine Panic in `/api/create`
Mar 26th 2026
flex0geek
•
duplicate
High
DoS via integer overflow in readGGUFString (GGUF parser)
Mar 26th 2026
radikhoroshev
•
duplicate
High
Denial of Service via Unbounded Memory Allocation in GGUF String Parsing
Mar 19th 2026
twsky100
•
duplicate
High
DNS Rebinding Bypass of Host Validation Allows Cross-Origin API Access
Mar 19th 2026
twsky100
•
duplicate
High
DNS Rebinding bypasses allowedHostsMiddleware via .local/.internal TLD wildcard
Mar 19th 2026
eistee82
•
duplicate
High
Server Crash via GGUF String Length Integer Truncation
Mar 26th 2026
yjk0805
•
duplicate
High
Server Crash via Unchecked Type Assertion in `/api/create` Info Field
Mar 26th 2026
yjk0805
•
duplicate
High
Division-by-Zero Server Crash via `general.alignment = 0` in GGUF Parser
Mar 26th 2026
yjk0805
•
duplicate
High
DNS Rebinding Host Bypass
Mar 19th 2026
appsecguardian-hash
•
duplicate
Critical
OOM DoS via Unbounded Safetensors Allocation in imagegen Module (2 Locations)
Mar 9th 2026
iamveene
•
self closed
OOM DoS via Unbounded Memory Allocation in Safetensors and GGUF Model Parsers
Mar 9th 2026
iamveene
•
self closed
Zip Slip in macOS Auto-Updater Allows Arbitrary File Write via Path Traversal
Mar 9th 2026
iamveene
•
self closed
DNS Rebinding Bypass via allowedHostsMiddleware Allows Cross-Origin API Access
Mar 9th 2026
iamveene
•
self closed
DNS Rebinding via .localhost TLD Bypass Allows Browser-Based Attack on Local Oll...
Mar 8th 2026
uncle-enzo
•
duplicate
High
Browser-triggerable unauthenticated panic in `/api/create` via unsafe type asser...
Mar 5th 2026
maru1009
•
duplicate
Medium
Unauthenticated DoS via Panic in /api/create Due to Unsafe Type Assertion
Mar 3rd 2026
mstscmsn
•
duplicate
High
Remote DoS via Integer Overflow in Multimodal Image Tokenization
Mar 1st 2026
fatmo666
•
duplicate
High
Unbounded Memory Allocation (OOM/DoS) in `x/imagegen` SafeTensors Parser
Feb 28th 2026
ashfiexe
•
duplicate
High
Integer Signedness Bug in GGUF readString() Bypasses Bounds Check — Denial of Se...
Feb 23rd 2026
nottiboy137
•
duplicate
Medium
Missing Bounds Check on SafeTensors data_offsets Causes Index Out-of-Bounds Pani...
Feb 23rd 2026
nottiboy137
•
duplicate
High
Integer Overflow in SafeTensors Header Size Causes Server Crash — Denial of Serv...
Feb 23rd 2026
nottiboy137
•
duplicate
High
Unvalidated SafeTensors Header Size Causes Server Crash via OOM/Panic in parseSa...
Feb 22nd 2026
shima-coder
•
duplicate
High
Remote Denial of Service via Malicious Registry www-authenticate Header Parsing
Mar 29th 2026
akhmittra
•
duplicate
Medium
DoS - Memory Exhaustion in GGUF Parsing logic
Mar 19th 2026
groscins
•
duplicate
High
Safetensors parser unbounded memory allocation crashes server process (patch mis...
Feb 22nd 2026
jungmine
•
duplicate
High
Improper safetensors header-length validation leads to DoS
Feb 22nd 2026
anhvuleduc
•
duplicate
High
GGUF String Length Integer Overflow lead to DOS
Mar 19th 2026
anhvuleduc
•
duplicate
High
DNS Rebinding Bypass via .local mDNS — Incomplete Fix for CVE-2024-28224
Mar 8th 2026
responsiblereport10
•
duplicate
High
Integer Overflow in GGUF Array Size Parsing Causes DoS via Panic
Feb 4th 2026
222n5
•
self closed
Heap Buffer Overflow and Integer Overflow in Image Processing Leading to DoS and...
Mar 1st 2026
malhyuk
•
duplicate
High
Denial of Service (OOM) via Unbounded Allocation
Jan 10th 2026
fatihhcelik
•
duplicate
High
Blind SSRF in PullModel allows Internal Network Scanning & Cloud Metadata Exfilt...
Jan 9th 2026
bademeischta
•
duplicate
High
Server-Side Request Forgery Enables Internal Network Scanning and Cloud Metadata...
Jan 9th 2026
abdallaabdalrhman
•
duplicate
Critical
systemd unit directive injection via unescaped $PATH in installer leads to root...
Apr 3rd 2026
asoticdin
•
pending
Windows updater executes unsigned installer from staging (arbitrary code executi...
Apr 3rd 2026
asoticdin
•
duplicate
High
Blind SSRF Bypass via Unsafe HTTP Client Redirect Policy (http.DefaultClient)
Apr 2nd 2026
yasinseyhun
•
pending
Unauthenticated Remote Denial of Service (DoS) via Malformed GGUF File Parsing (...
Jan 2nd 2026
yasinseyhun
•
duplicate
High
Supply Chain Remote Code Execution via Insecure Update Mechanism
Mar 26th 2026
hackwidmaddy
•
pending
Missing Cryptographic Signature Verification in Windows Update Mechanism leading...
Mar 26th 2026
shash-hq
•
pending
System Prompt Injection via Template Markers Bypasses System Instructions
Mar 24th 2026
velvolution-claudeverse
•
pending
Unbounded string reflection of model name
Mar 21st 2026
ndren
•
pending
Arbitrary File Read in Ollama Client
Mar 16th 2026
kr1shna4garwal
•
pending
SSRF via Location Header Redirect in Blob Upload
Mar 9th 2026
sellamiam
•
pending
ZIP Slip Path Traversal in macOS Auto-Updater allows arbitrary file write
Mar 2nd 2026
vitalysim
•
pending
Ollama Desktop Stored XSS via Unsanitized AI Response Rendering
Feb 21st 2026
pyozzi-toss
•
pending
Ollama Exposes the Local Model Directory via Network Requests
Nov 23rd 2025
ylwango613
•
duplicate
Medium
Unauthenticated Blind SSRF in /api/pull and /api/push allowing Internal Network...
Jan 9th 2026
jarcis-cy
•
duplicate
High
Reading a malicious GGUF file causes out-of-bounds read and crash
Jan 2nd 2026
ylwango613
•
duplicate
High
Ollama Token-Length Overflow Causes Denial of Service
Feb 16th 2026
ylwango613
•
pending
JavaScript Injection via Deeplink Handler in Ollama Desktop for Windows
Feb 15th 2026
pyozzi-toss
•
pending
Unauthenticated network access to model management and inference via Docker defa...
Jan 31st 2026
sleeptok3n
•
pending
Blind Server-Side Request Forgery from custom model files to internal endpoints...
Nov 6th 2025
sim4n6
•
duplicate
Medium
A malformed image can lead to DoS due to unchecked null pointer dereference via...
Mar 20th 2026
weblover12
•
self closed
Ollama API allows anyone to do anything remotely when Ollama is exposed to the n...
Nov 6th 2025
r4356th
•
duplicate
Critical
Ollama /api/create Unauthenticated DoS via Unsafe Interface Conversion
Jan 2nd 2026
weblover12
•
duplicate
High
A malicious request can lead to panic DOS due to unsafe type conversion in Creat...
Dec 24th 2025
tianstcht
•
pending
Denial of Service (DoS) attacks triggered by malicious private registry
Sep 4th 2025
h1b1ki
•
duplicate
High
Show more...
CRITICAL
$1500
HIGH
$750
MEDIUM
$125
LOW
$20