PT-2026-3790 · Ollama · Ollama

Published

2026-01-21

·

Updated

2026-02-08

·

CVE-2025-66960

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Ollama versions prior to 0.12.10
Description An issue exists in the readGGUFV1String() function within the Ollama large language model (LLM) launch and management system. Insufficient input validation in this function can allow a remote attacker to cause a denial of service. The issue resides in the fs/ggml/gguf.go file, where the readGGUFV1String() function reads a string length from untrusted GGUF metadata.
Recommendations Update to version 0.12.10 or later.

Exploit

Fix

DoS

Resource Exhaustion

RCE

Weakness Enumeration

Related Identifiers

BDU:2026-00974
CVE-2025-66960
PYSEC-2026-102

Affected Products

Ollama