Oligo Security disclosed six issues in Ollama, the open-source platform for serving large language models locally and remotely. Four received CVE identifiers: CVE-2024-39719, CVE-2024-39720, CVE-2024-39721, and CVE-2024-39722. The reported flaws affect the CreateModel and push APIs and can allow application crashes, resource-exhaustion denial of service, and disclosure of whether files exist on the host.
Ollama fixed CVE-2024-39720, CVE-2024-39721, and CVE-2024-39722 in version 0.1.46, while Oligo said CVE-2024-39719 remained unresolved in version 0.3.14. Oligo also identified unauthenticated pull and push management endpoints as potential routes for model poisoning and model theft, although Ollama maintainers disputed those findings as vulnerabilities. The researchers estimated about 10,000 internet-exposed Ollama IP addresses and assessed roughly one quarter as vulnerable to the reported issues.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
MITRE assigned CVE-2024-39719, CVE-2024-39720, CVE-2024-39721, and CVE-2024-39722 to four of the Ollama vulnerabilities reported by Oligo.
Ollama released version 0.1.46, fixing the denial-of-service issues described in the advisory, including CVE-2024-39720 and CVE-2024-39721, as well as the /api/push path-traversal/file-disclosure issue CVE-2024-39722.
Ollama maintainers confirmed four of Oligo's reported issues and began developing fixes. They did not acknowledge the reported model-poisoning and model-theft conditions as vulnerabilities.
Oligo reported six security issues affecting Ollama, including CreateModel API denial-of-service and file-disclosure flaws, as well as disputed unauthenticated model-pull and model-push issues. Ollama maintainers later disputed the model-poisoning and model-theft reports.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.