CVE-2025-66960: Input Validation
Published Jan 21, 2026
·Updated
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata
Affected Software
2 affected components
npm/ollama=0.12.10
Ollama Ollama=0.12.10
Event History
Jan 21, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66960?
CVE-2025-66960 is classified as a denial of service vulnerability.
2
How do I fix CVE-2025-66960?
To fix CVE-2025-66960, you should upgrade to the latest version of ollama beyond version 0.12.10.
3
What software is affected by CVE-2025-66960?
CVE-2025-66960 affects ollama version 0.12.10.
4
Can CVE-2025-66960 be exploited remotely?
Yes, CVE-2025-66960 can be exploited by a remote attacker.
5
What function is responsible for the vulnerability in CVE-2025-66960?
The function readGGUFV1String in fs/ggml/gguf.go is responsible for the vulnerability in CVE-2025-66960.