PT-2025-21626 · Unknown · Ollama Server

Published

2025-05-16

·

Updated

2025-07-07

·

CVE-2025-1975

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Ollama server version 0.5.11
Description: A Denial of Service (DoS) attack can be caused by a malicious user customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the "/api/pull" endpoint, which can lead to a server crash.
Recommendations: As a temporary workaround, consider disabling access to the "/api/pull" endpoint until a patch is available. Restrict access to the Ollama server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Validation of Array Index

Weakness Enumeration

Related Identifiers

CVE-2025-1975
GHSA-WRH5-CMWX-Q2QR
GO-2025-3695
OPENSUSE-SU-2025:15159-1
PYSEC-2025-145

Affected Products

Ollama Server