An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata
{ "versions": [ { "introduced": "0" }, { "last_affected": "0.12.10-NA" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66960.json"