[GH-ISSUE #14817] Security: High-Severity Report Pending on Huntr.com (Remote DoS via Signed Integer Overflow) #9566

Open
opened 2026-04-12 22:28:51 -05:00 by GiteaMirror · 0 comments
Owner

Originally created by @nusedsec on GitHub (Mar 13, 2026).
Original GitHub issue: https://github.com/ollama/ollama/issues/14817

Hi Ollama Team,

I am writing to notify you regarding a high-severity security vulnerability report I submitted via https://www.google.com/search?q=Huntr.com on February 23rd.

The report describes a Remote DoS (Signed Integer Overflow) that can crash the LLM runner with a single request. It has been awaiting maintainer review for over 20 days.

To ensure the security and availability of Ollama for all users, could someone from the security or maintainer team please check the Huntr dashboard and review the submission?

Huntr Report Link: [https://huntr.com/bounties/0a890d9e-64b5-489a-a6d9-aecf18430def]

Thank you for your amazing work on Ollama!

Best regards,

nused_sec

Originally created by @nusedsec on GitHub (Mar 13, 2026). Original GitHub issue: https://github.com/ollama/ollama/issues/14817 Hi Ollama Team, I am writing to notify you regarding a high-severity security vulnerability report I submitted via https://www.google.com/search?q=Huntr.com on February 23rd. The report describes a Remote DoS (Signed Integer Overflow) that can crash the LLM runner with a single request. It has been awaiting maintainer review for over 20 days. To ensure the security and availability of Ollama for all users, could someone from the security or maintainer team please check the Huntr dashboard and review the submission? Huntr Report Link: [https://huntr.com/bounties/0a890d9e-64b5-489a-a6d9-aecf18430def] Thank you for your amazing work on Ollama! Best regards, nused_sec
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/ollama#9566