[GH-ISSUE #13895] Question: Status of security reports sent to hello@ollama.com #55604

Closed
opened 2026-04-29 09:28:29 -05:00 by GiteaMirror · 1 comment
Owner

Originally created by @ylwango613 on GitHub (Jan 25, 2026).
Original GitHub issue: https://github.com/ollama/ollama/issues/13895

Originally assigned to: @jmorganca on GitHub.

Hi Ollama team,
I sent three security vulnerability reports to hello@ollama.com over a week ago (including one about "Ollama's lack of input restrictions on JSON format leads to DoS"), but haven't received any response yet.
I wanted to check:

  • Are my reports under review?
  • Is hello@ollama.com the correct channel for security disclosures?

I understand security reviews take time. I just want to make sure the reports didn't get lost and that I'm following the right process.
Happy to provide more details if needed. Thanks for your work on Ollama!

By the way, a little bug about issue:

Image

But I got:

Image
Originally created by @ylwango613 on GitHub (Jan 25, 2026). Original GitHub issue: https://github.com/ollama/ollama/issues/13895 Originally assigned to: @jmorganca on GitHub. Hi Ollama team, I sent three security vulnerability reports to [hello@ollama.com](mailto:hello@ollama.com) over a week ago (including one about "Ollama's lack of input restrictions on JSON format leads to DoS"), but haven't received any response yet. I wanted to check: - Are my reports under review? - Is [hello@ollama.com](mailto:hello@ollama.com) the correct channel for security disclosures? I understand security reviews take time. I just want to make sure the reports didn't get lost and that I'm following the right process. Happy to provide more details if needed. Thanks for your work on Ollama! By the way, a little bug about issue: <img width="1078" height="650" alt="Image" src="https://github.com/user-attachments/assets/13d29484-60c4-41d6-99c1-82aff572768b" /> But I got: <img width="1908" height="846" alt="Image" src="https://github.com/user-attachments/assets/84f2ba7d-2ac8-4c8b-aae2-9f19f30fc7e4" />
Author
Owner

@jmorganca commented on GitHub (Jan 25, 2026):

@ylwango613 sorry about the delay here. Will respond via email. Thanks for creating an issue and appreciate the kind words (and thanks for finding that docs bug!)

<!-- gh-comment-id:3796165540 --> @jmorganca commented on GitHub (Jan 25, 2026): @ylwango613 sorry about the delay here. Will respond via email. Thanks for creating an issue and appreciate the kind words (and thanks for finding that docs bug!)
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/ollama#55604