[GH-ISSUE #8020] Nancy finds security vulnerabilities #82814

Open
opened 2026-05-09 15:50:39 -05:00 by GiteaMirror · 0 comments
Owner

Originally created by @mitar on GitHub (Dec 10, 2024).
Original GitHub issue: https://github.com/ollama/ollama/issues/8020

What is the issue?

It finds:

The latest stable Ollama version does not fix them, so I am opening an issue to track that.

OS

Linux

GPU

Intel

CPU

Intel

Ollama version

0.5.1

Originally created by @mitar on GitHub (Dec 10, 2024). Original GitHub issue: https://github.com/ollama/ollama/issues/8020 ### What is the issue? It finds: * [CVE-2024-8063](https://ossindex.sonatype.org/vulnerability/CVE-2024-8063?component-type=golang&component-name=github.com%2Follama%2Follama&utm_source=nancy-client&utm_medium=integration&utm_content=1.0.46) CWE-369: Divide By Zero * [CVE-2024-39719](https://ossindex.sonatype.org/vulnerability/CVE-2024-39719?component-type=golang&component-name=github.com%2Follama%2Follama&utm_source=nancy-client&utm_medium=integration&utm_content=1.0.46) CWE-209: Information Exposure Through an Error Message The latest stable Ollama version does not fix them, so I am opening an issue to track that. ### OS Linux ### GPU Intel ### CPU Intel ### Ollama version 0.5.1
GiteaMirror added the bug label 2026-05-09 15:50:39 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/ollama#82814