Vulnerabilities
Vulnerable Software
Ollama:  >> Ollama  >> 0.5.11  Security Vulnerabilities
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.
CVSS Score
9.8
EPSS Score
0.002
Published
2025-12-18
A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the /api/pull endpoint, which can lead to a server crash.
CVSS Score
7.5
EPSS Score
0.002
Published
2025-05-16


Contact Us

Shodan ® - All rights reserved