Uncontrolled Memory Allocation Vulnerability in Ollama by Ollama
CVE-2026-65315

8.7HIGH

Key Information:

Vendor

Ollama

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-65315?

Ollama version HEAD f0078ae contains a vulnerability in its GGUF metadata parser that enables remote attackers to exploit uncontrolled memory allocation. By crafting a GGUF file with manipulated length and count fields, attackers can trigger fatal errors, causing the server to run out of memory or crash entirely. This vulnerability allows the upload of specially crafted sub-1KB GGUF files through designated API endpoints, leading to a denial of service as the server fails to adequately validate allocation sizes against the total file size.

Affected Version(s)

Ollama 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.