Skip to content
HighVulnerabilityLLM-specific

GHSA-v464-r2r9-www7: Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP

Published
Record updated
View JSON
Affected
  • github.com/ollama/ollama <= 0.3.14
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.7%

Summary

CVE-2024-12886 affects the Ollama server in the Go module github.com/ollama/ollama, versions <= 0.3.14. A malicious API server can send a gzip bomb HTTP response, which causes an Out-Of-Memory condition and crashes the Ollama server. The flaw sits in the makeRequestWithRetry and getAuthorizationToken functions, which read the response body with io.ReadAll.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.