PYSEC-2026-3450

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/ollama/PYSEC-2026-3450.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-3450
Aliases
Withdrawn
2026-07-16T11:24:45Z
Published
2026-07-13T22:16:46Z
Modified
2026-07-20T08:45:07Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the downloadBlob function. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated array. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-27277.

References

Affected packages

PyPI / ollama

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.7.1-NA

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/ollama/PYSEC-2026-3450.yaml"