Denial of Service Vulnerability in Ollama by Ollama Inc.
CVE-2025-66960
7.5HIGH
What is CVE-2025-66960?
A vulnerability exists in Ollama v0.12.10 that allows remote attackers to exploit the function readGGUFV1String within the fs/ggml/gguf.go file, potentially resulting in a denial of service condition. This occurs when the function reads an untrusted string length from GGUF metadata, which may lead to unexpected behavior and service disruption.
