HighVulnerabilityLLM-specific
GHSA-v464-r2r9-www7: Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP
- Identifiers
- CVE-2024-12886GHSA-v464-r2r9-www7
- Published
- Record updated
- Affected
- github.com/ollama/ollama <= 0.3.14
- Fixed in
- No fixed version was stated when the source was last read.
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.7%
Summary
CVE-2024-12886 affects the Ollama server in the Go module github.com/ollama/ollama, versions <= 0.3.14. A malicious API server can send a gzip bomb HTTP response, which causes an Out-Of-Memory condition and crashes the Ollama server. The flaw sits in the makeRequestWithRetry and getAuthorizationToken functions, which read the response body with io.ReadAll.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- github.com/ollama/ollamaGoLLM dependency since 2023-07-08 · 3 tracked dependents
Topics
Related items
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories
- MediumHermes Agent - Pre-Authentication Memory ExhaustionSimilar attack · Tenable Research Advisories
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database