A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the /api/pull endpoint, which can lead to a server crash.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-15424 Ollama Server Vulnerable to Denial of Service (DoS) Attack
Github GHSA Github GHSA GHSA-wrh5-cmwx-q2qr Ollama Server Vulnerable to Denial of Service (DoS) Attack
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 24 Jun 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Ollama
Ollama ollama
CPEs cpe:2.3:a:ollama:ollama:0.5.11:*:*:*:*:*:*:*
Vendors & Products Ollama
Ollama ollama

Tue, 20 May 2025 02:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 16 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 May 2025 08:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the /api/pull endpoint, which can lead to a server crash.
Title Improper Validation of Array Index in ollama/ollama
Weaknesses CWE-129
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-05-16T15:50:11.815Z

Reserved: 2025-03-04T21:57:53.651Z

Link: CVE-2025-1975

cve-icon Vulnrichment

Updated: 2025-05-16T15:50:06.022Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-16T09:15:17.980

Modified: 2025-06-24T16:40:44.220

Link: CVE-2025-1975

cve-icon Redhat

Severity : Important

Publid Date: 2025-05-16T08:25:57Z

Links: CVE-2025-1975 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses