{"schema_version":"1.7.5","id":"GHSA-wrh5-cmwx-q2qr","published":"2025-05-16T09:30:36Z","modified":"2026-06-10T12:11:03.946507195Z","aliases":["CVE-2025-1975","GO-2025-3695"],"related":["CGA-63jp-hpjv-73mh"],"summary":"Ollama Server Vulnerable to Denial of Service (DoS) Attack","details":"A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the /api/pull endpoint, which can lead to a server crash.","affected":[{"package":{"name":"github.com/ollama/ollama","ecosystem":"Go","purl":"pkg:golang/github.com/ollama/ollama"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.5.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-wrh5-cmwx-q2qr/GHSA-wrh5-cmwx-q2qr.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1975"},{"type":"PACKAGE","url":"https://github.com/ollama/ollama"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/ollama/PYSEC-2025-145.yaml"},{"type":"WEB","url":"https://huntr.com/bounties/921ba5d4-f1d0-4c66-9764-4f72dffe7acd"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2025-3695"}],"database_specific":{"cwe_ids":["CWE-129"],"github_reviewed":true,"github_reviewed_at":"2025-05-17T15:10:13Z","nvd_published_at":"2025-05-16T09:15:17Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}