Ollama Vulnerabilities

pip LLM Inference

AI Threat Alert tracks 35 known vulnerabilities in Ollama, 6 rated critical — an AI/ML llm inference in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
84
Risk Score
35
Total CVEs
6
Critical
pip
Ecosystem
Sep 28, 2026
Last CVE
20%
Patch Rate
26d
Avg Time to Patch
181,782 stars 18,018 forks 4,107 issues 1,779 dependents Last push Sep 26, 2026
View on GitHub

Known Vulnerabilities (35 total, page 1 of 2)

Severity CVE ID Summary CVSS Published
HIGH GHSA-456v-xq2p-r4cj code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78) 7.8 Sep 28, 2026 HIGH CVE-2026-56676 9router: Image prefetch DNS rebinding allows SSRF to internal services 7.4 Sep 23, 2026 HIGH CVE-2026-58197 ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement 8.8 Sep 18, 2026 HIGH CVE-2026-59158 nuxt-ollama: API key leaked in public SSR payload 7.5 Sep 9, 2026 MEDIUM CVE-2026-86289 Ollama: integer overflow in GGUF decoder causes DoS 4.3 Sep 7, 2026 HIGH CVE-2026-85180 Ollama: SSRF via unvalidated model-pull redirects 7.5 Sep 3, 2026 HIGH CVE-2026-65315 Ollama: crafted GGUF file crashes inference server 7.5 Jul 21, 2026 UNKNOWN CVE-2026-15685 Ollama: downloadBlob array index bug enables unauth DoS -- Jul 13, 2026 HIGH CVE-2026-5757 Ollama: unauthenticated heap memory disclosure 7.5 Jun 26, 2026 CRITICAL CVE-2026-46339 9router: unauthenticated RCE exposes LLM API keys 10.0 May 19, 2026 MEDIUM CVE-2026-43979 local-deep-research: HTML injection enables SSRF via WeasyPrint 5.0 May 11, 2026 CRITICAL CVE-2026-44007 vm2: sandbox escape via nesting:true enables RCE 9.1 May 7, 2026 CRITICAL CVE-2026-7482 Ollama: heap OOB read leaks API keys and chat data 9.1 May 4, 2026 CRITICAL CVE-2026-42249 Ollama: path traversal + unsigned update = silent RCE 9.8 Apr 29, 2026 CRITICAL CVE-2026-42248 Ollama: silent auto-update bypasses signature check on Windows 9.8 Apr 29, 2026 LOW CVE-2026-7020 Ollama: path traversal in tensor model transfer handler 3.7 Apr 26, 2026 HIGH CVE-2025-66960 ollama: Input Validation flaw enables exploitation 7.5 Jan 21, 2026 HIGH CVE-2025-66959 ollama: Input Validation flaw enables exploitation 7.5 Jan 21, 2026 HIGH CVE-2025-15514 ollama: security flaw enables exploitation 7.5 Jan 12, 2026 CRITICAL CVE-2025-63389 ollama: Missing Auth allows unauthenticated access 9.8 Dec 18, 2025 MEDIUM CVE-2025-44779 Ollama: arbitrary file deletion via /api/pull 6.6 Aug 7, 2025 MEDIUM CVE-2025-51471 Ollama: auth token hijack via crafted WWW-Authenticate 6.9 Jul 22, 2025 UNKNOWN CVE-2025-1975 Ollama: DoS via malicious manifest in /api/pull -- May 16, 2025 HIGH CVE-2025-0317 Ollama: DoS via malicious GGUF model file upload 7.5 Mar 20, 2025 HIGH CVE-2025-0315 Ollama: GGUF model upload causes memory exhaustion DoS 7.5 Mar 20, 2025

Showing 1–25 of 35

Frequently asked questions

What is Ollama?

Ollama is an AI/ML llm inference tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Ollama have?

Ollama has 35 known CVEs, 6 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Ollama distributed in?

Ollama is distributed via the pip ecosystem and categorized as llm inference.

Where does the Ollama vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Ollama?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Ollama in your stack

Get instant alerts when new vulnerabilities affect Ollama. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring