CVE-2024-39721: Ollama

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be set to /dev/random, which is blocking, causing the goroutine to run infinitely (even after the HTTP request is aborted by the client).

Affected products

  • Ollama Ollama: before 0.1.34 (fixed in 0.1.34)

Published 2024-10-31. Last modified 2026-06-17.