HIGH7.5
GHSA-fccc-8m69-8r78
Ollama Allocation of Resources Without Limits or Throttling vulnerability
Details
A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate unlimited memory, leading to a Denial of Service (DoS) attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/ollama/ollama
Introduced in:
0No fixed version published yet for github.com/ollama/ollama (go modules). Pin to a known-safe version or switch to an alternative.