ZDI-CAN-27277: ZDI-26-403: (0Day) Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloadBlob function. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated array. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-15685.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-26-403 - Compensating control
Mitigate the remote denial-of-service risk by restricting network access to Ollama so only trusted clients can reach it (since authentication is not required to exploit).
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27277?
The severity of ZDI-CAN-27277 is high, rated at 7.5.
What type of vulnerability is ZDI-CAN-27277?
ZDI-CAN-27277 is classified as a denial-of-service vulnerability.
How do I fix ZDI-CAN-27277?
To fix ZDI-CAN-27277, ensure you update Ollama to the latest version that addresses this vulnerability.
What software is affected by ZDI-CAN-27277?
ZDI-CAN-27277 affects installations of Ollama.
Is authentication required to exploit ZDI-CAN-27277?
No, authentication is not required to exploit the ZDI-CAN-27277 vulnerability.