CVE-2025-66959: Input Validation
Published Jan 21, 2026
·Updated
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder
Affected Software
2 affected components
npm/ollama
Ollama Ollama=0.12.10
Event History
Jan 21, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66959?
CVE-2025-66959 has a high severity rating due to its potential to cause a denial of service.
2
How do I fix CVE-2025-66959?
To fix CVE-2025-66959, update to the latest version of the ollama software that addresses this vulnerability.
3
What type of attack does CVE-2025-66959 enable?
CVE-2025-66959 enables remote attackers to cause a denial of service via the GGUF decoder.
4
Which software is affected by CVE-2025-66959?
CVE-2025-66959 affects ollama version 0.12.10.
5
What mitigation strategies exist for CVE-2025-66959?
Mitigation for CVE-2025-66959 includes applying patches and monitoring software for unusual requests to the GGUF decoder.