A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the /api/pull endpoint, which can lead to a server crash.
Metrics
Affected Vendors & Products
References
History
Fri, 16 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 16 May 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the /api/pull endpoint, which can lead to a server crash. | |
Title | Improper Validation of Array Index in ollama/ollama | |
Weaknesses | CWE-129 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-05-16T15:50:11.815Z
Reserved: 2025-03-04T21:57:53.651Z
Link: CVE-2025-1975

Updated: 2025-05-16T15:50:06.022Z

Status : Awaiting Analysis
Published: 2025-05-16T09:15:17.980
Modified: 2025-05-16T14:42:18.700
Link: CVE-2025-1975

No data.