8000 x/vulndb: potential Go vuln in github.com/ollama/ollama: GHSA-wrh5-cmwx-q2qr · Issue #3695 · golang/vulndb · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

x/vulndb: potential Go vuln in github.com/ollama/ollama: GHSA-wrh5-cmwx-q2qr #3695

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
GoVulnBot opened this issue May 17, 2025 · 1 comment

Comments

@GoVulnBot
Copy link

Advisory GHSA-wrh5-cmwx-q2qr references a vulnerability in the following Go modules:

Module
github.com/ollama/ollama

Description:
A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the /api/pull endpoint, which can lead to a server crash.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/ollama/ollama
      vulnerable_at: 0.7.0
summary: Ollama Server Vulnerable to Denial of Service (DoS) Attack in github.com/ollama/ollama
cves:
    - CVE-2025-1975
ghsas:
    - GHSA-wrh5-cmwx-q2qr
references:
    - advisory: https://github.com/advisories/GHSA-wrh5-cmwx-q2qr
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-1975
    - web: https://huntr.com/bounties/921ba5d4-f1d0-4c66-9764-4f72dffe7acd
source:
    id: GHSA-wrh5-cmwx-q2qr
    created: 2025-05-17T16:02:24.673701905Z
review_status: UNREVIEWED

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/674495 mentions this issue: data/reports: add GO-2025-3695

gopherbot pushed a commit that referenced this issue May 22, 2025
  - data/reports/GO-2025-3695.yaml

Updates #3695

Change-Id: Iad4306acd112da47fa4a6bd68f6a00c70f7ae914
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/674495
Reviewed-by: Damien Neil <dneil@google.com>
LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Auto-Submit: Neal Patel <nealpatel@google.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants
0