CVE-2025-1975: Improper Validation of Array Index in ollama/ollama
A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the /api/pull endpoint, which can lead to a server crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1975?
CVE-2025-1975 is classified as a Denial of Service (DoS) vulnerability.
How do I fix CVE-2025-1975?
To mitigate CVE-2025-1975, upgrade to the latest version of Ollama Server that addresses the vulnerability.
What can an attacker do with CVE-2025-1975?
An attacker can exploit CVE-2025-1975 to cause a Denial of Service attack by manipulating the manifest content.
Which versions of Ollama Server are affected by CVE-2025-1975?
Ollama Server version 0.5.11 is affected by CVE-2025-1975.
Where does the vulnerability CVE-2025-1975 occur within the software?
CVE-2025-1975 occurs when downloading a model via the /api/pull endpoint due to improper validation of array index access.