Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 04/05/2026, 00:30:13 UTC Added: 04/05/2026, 05:47:12 UTC |
0 An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata Join the discussion | CVE Database V5 | 01/21/2026, 00:00:00 UTC Added: 01/21/2026, 19:09:11 UTC |
0 An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder Join the discussion | CVE Database V5 | 01/21/2026, 00:00:00 UTC Added: 01/21/2026, 17:50:56 UTC |
0 A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations. Join the discussion | CVE Database V5 | 12/18/2025, 00:00:00 UTC Added: 12/18/2025, 15:26:34 UTC |
0 Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint. Join the discussion | CVE Database V5 | 07/22/2025, 00:00:00 UTC Added: 07/22/2025, 18:46:08 UTC |
0 An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered when a malicious API server responds with a gzip bomb HTTP response, leading to the `ollama` server crashing. The vulnerability is present in the `makeRequestWithRetry` and `getAuthorizationToken` functions, which use `io.ReadAll` to read the response body. This can result in excessive memory usage and a Denial of Service (DoS) condition. Join the discussion | CVE Database V5 | 03/20/2025, 10:10:28 UTC Added: 10/15/2025, 13:01:25 UTC |
0 An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/push route. Join the discussion | CVE Database V5 | 10/31/2024, 00:00:00 UTC Added: 02/25/2026, 21:41:27 UTC |
0 An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement pointing to the attacker-controlled blob file, the attacker can crash the application through the CreateModel route, leading to a segmentation fault (signal SIGSEGV: segmentation violation). Join the discussion | CVE Database V5 | 10/31/2024, 00:00:00 UTC Added: 02/25/2026, 21:41:27 UTC |
0 extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory. Join the discussion | CVE Database V5 | 08/29/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:09 UTC |
Showing 1 to 9 of 9 results