[GH-ISSUE #15262] Vulnerability responsible disclosure #35521

Open
opened 2026-04-22 20:05:29 -05:00 by GiteaMirror · 0 comments
Owner

Originally created by @CERT-PL-CNA on GitHub (Apr 3, 2026).
Original GitHub issue: https://github.com/ollama/ollama/issues/15262

Hi,
as CERT.PL CNA (CVE Numbering Authority) we were requested to assign CVEs for vulnerabilities found in in this project. The tester reported you the details through "Report a vulnerability" function and we mailed you at hello@ollama.com (from cert@cert.pl), both left with no reaction throughout last weeks.

We would like to know how should the vulnerabilities be reported so it's effective?
We are planning to publish the CVEs by the end of April 2026.

Originally created by @CERT-PL-CNA on GitHub (Apr 3, 2026). Original GitHub issue: https://github.com/ollama/ollama/issues/15262 Hi, as CERT.PL CNA (CVE Numbering Authority) we were requested to assign CVEs for vulnerabilities found in in this project. The tester reported you the details through "Report a vulnerability" function and we mailed you at hello@ollama.com (from cert@cert.pl), both left with no reaction throughout last weeks. We would like to know how should the vulnerabilities be reported so it's effective? We are planning to publish the CVEs by the end of April 2026.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/ollama#35521