PT-2025-12311 · Ollama · Ollama

Published

2025-03-20

·

Updated

2025-04-02

·

CVE-2025-0315

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ollama/ollama versions 0.3.14 and earlier
Description A malicious user can create a customized GGUF model file, upload it to the Ollama server, and create it, causing the server to allocate unlimited memory. This leads to a Denial of Service (DoS) attack.
Recommendations For versions 0.3.14 and earlier, consider restricting access to the model file upload feature to prevent malicious users from uploading customized GGUF model files until a patch is available. As a temporary workaround, monitor server memory allocation closely to detect and mitigate potential DoS attacks.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2025-0315
GHSA-FCCC-8M69-8R78
GO-2025-3557
OPENSUSE-SU-2025:14955-1

Affected Products

Ollama