Ollama Server Vulnerable to Denial of Service (DoS) Attack
High severity
GitHub Reviewed
Published
May 16, 2025
to the GitHub Advisory Database
•
Updated May 22, 2025
Description
Published by the National Vulnerability Database
May 16, 2025
Published to the GitHub Advisory Database
May 16, 2025
Reviewed
May 17, 2025
Last updated
May 22, 2025
A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the /api/pull endpoint, which can lead to a server crash.
References