[GH-ISSUE #15262] Vulnerability responsible disclosure #56274

Open
opened 2026-04-29 10:33:24 -05:00 by GiteaMirror · 2 comments
Owner

Originally created by @CERT-PL-CNA on GitHub (Apr 3, 2026).
Original GitHub issue: https://github.com/ollama/ollama/issues/15262

Hi,
as CERT.PL CNA (CVE Numbering Authority) we were requested to assign CVEs for vulnerabilities found in in this project. The tester reported you the details through "Report a vulnerability" function and we mailed you at hello@ollama.com (from cert@cert.pl), both left with no reaction throughout last weeks.

We would like to know how should the vulnerabilities be reported so it's effective?
We are planning to publish the CVEs by the end of April 2026.

Originally created by @CERT-PL-CNA on GitHub (Apr 3, 2026). Original GitHub issue: https://github.com/ollama/ollama/issues/15262 Hi, as CERT.PL CNA (CVE Numbering Authority) we were requested to assign CVEs for vulnerabilities found in in this project. The tester reported you the details through "Report a vulnerability" function and we mailed you at hello@ollama.com (from cert@cert.pl), both left with no reaction throughout last weeks. We would like to know how should the vulnerabilities be reported so it's effective? We are planning to publish the CVEs by the end of April 2026.
Author
Owner

@CERT-PL-CNA commented on GitHub (Apr 23, 2026):

Hi,

In case of no answer from your side we will publish CVE entries according to information provided by the finder on 29.04.2026

<!-- gh-comment-id:4304681580 --> @CERT-PL-CNA commented on GitHub (Apr 23, 2026): Hi, In case of no answer from your side we will publish CVE entries according to information provided by the finder on 29.04.2026
Author
Owner

@CERT-PL-CNA commented on GitHub (Apr 29, 2026):

Hi

As mentioned before, we have published the CVEs:

https://cert.pl/en/posts/2026/04/CVE-2026-42248/

https://www.cve.org/CVERecord?id=CVE-2026-42248
https://www.cve.org/CVERecord?id=CVE-2026-42249

Kind regards,
CSIRT NASK / CERT Polska
cert.pl/en/

<!-- gh-comment-id:4343481071 --> @CERT-PL-CNA commented on GitHub (Apr 29, 2026): Hi As mentioned before, we have published the CVEs: https://cert.pl/en/posts/2026/04/CVE-2026-42248/ https://www.cve.org/CVERecord?id=CVE-2026-42248 https://www.cve.org/CVERecord?id=CVE-2026-42249 Kind regards, CSIRT NASK / CERT Polska cert.pl/en/
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/ollama#56274