Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: gnomeExtensions.ollama-usage-rings

Found 5 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-86289
2.1 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 2 weeks, 3 days ago Activity log
  • Created suggestion
Ollama GGUF Decoder gguf.go readGGUFV1String integer overflow

A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.31.2-rc1 is capable of addressing this issue. The patch is named 67b6a1c2d45321e0cb3c04a18073f9818de7724b. It is recommended to upgrade the affected component.

Affected products

Ollama
  • ==0.31.0
  • ==0.31.2-rc1
  • ==0.31.1

Matching in nixpkgs

pkgs.ollama

Get up and running with large language models locally

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gollama

Go manage your Ollama models

  • nixos-unstable -
    • nixos-unstable-small 2.0.5
  • nixos-26.05 -
    • nixos-26.05-small 2.0.4

pkgs.ollama-cpu

Get up and running with large language models locally

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-cuda

Get up and running with large language models locally, using CUDA for NVIDIA GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-rocm

Get up and running with large language models locally, using ROCm for AMD GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-vulkan

Get up and running with large language models locally, using Vulkan for generic GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pkgsRocm.ollama

Get up and running with large language models locally, using ROCm for AMD GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nextjs-ollama-llm-ui

Simple chat web interface for Ollama LLMs

  • nixos-unstable -
    • nixos-unstable-small 1.2.0
  • nixos-26.05 -
    • nixos-26.05-small 1.2.0

pkgs.gnomeExtensions.ollama-usage-rings

Shows your Ollama Cloud session and weekly usage as colored ring indicators in the GNOME top bar, with pace/burn-down details. Requires your own ollama.com session cookie (entered in the extension settings).

  • nixos-unstable -
    • nixos-unstable-small 3

Package maintainers

Untriaged
Permalink CVE-2026-15685
7.5 HIGH
  • CVSS version (CVSS): 3.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 2 months, 1 week ago Activity log
  • Created suggestion
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloadBlob function. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated array. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-27277.

References

Affected products

Ollama
  • ==0.7.1

Matching in nixpkgs

pkgs.ollama

Get up and running with large language models locally

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gollama

Go manage your Ollama models

  • nixos-unstable -
    • nixos-unstable-small 2.0.5
  • nixos-26.05 -
    • nixos-26.05-small 2.0.4

pkgs.ollama-cpu

Get up and running with large language models locally

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-cuda

Get up and running with large language models locally, using CUDA for NVIDIA GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-rocm

Get up and running with large language models locally, using ROCm for AMD GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-vulkan

Get up and running with large language models locally, using Vulkan for generic GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pkgsRocm.ollama

Get up and running with large language models locally, using ROCm for AMD GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nextjs-ollama-llm-ui

Simple chat web interface for Ollama LLMs

  • nixos-unstable -
    • nixos-unstable-small 1.2.0
  • nixos-26.05 -
    • nixos-26.05-small 1.2.0

pkgs.gnomeExtensions.ollama-usage-rings

Shows your Ollama Cloud session and weekly usage as colored ring indicators in the GNOME top bar, with pace/burn-down details. Requires your own ollama.com session cookie (entered in the extension settings).

  • nixos-unstable -
    • nixos-unstable-small 3

Package maintainers

Untriaged
Permalink CVE-2026-5757
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 2 months, 4 weeks ago Activity log
  • Created suggestion
There exists an unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

Affected products

Ollama
  • ==v0.13.5

Matching in nixpkgs

pkgs.ollama

Get up and running with large language models locally

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gollama

Go manage your Ollama models

  • nixos-unstable -
    • nixos-unstable-small 2.0.5
  • nixos-26.05 -
    • nixos-26.05-small 2.0.4

pkgs.ollama-cpu

Get up and running with large language models locally

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-cuda

Get up and running with large language models locally, using CUDA for NVIDIA GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-rocm

Get up and running with large language models locally, using ROCm for AMD GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-vulkan

Get up and running with large language models locally, using Vulkan for generic GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pkgsRocm.ollama

Get up and running with large language models locally, using ROCm for AMD GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nextjs-ollama-llm-ui

Simple chat web interface for Ollama LLMs

  • nixos-unstable -
    • nixos-unstable-small 1.2.0
  • nixos-26.05 -
    • nixos-26.05-small 1.2.0

pkgs.gnomeExtensions.ollama-usage-rings

Shows your Ollama Cloud session and weekly usage as colored ring indicators in the GNOME top bar, with pace/burn-down details. Requires your own ollama.com session cookie (entered in the extension settings).

  • nixos-unstable -
    • nixos-unstable-small 3

Package maintainers

Untriaged
Permalink CVE-2026-7482
9.1 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 4 months, 2 weeks ago Activity log
  • Created suggestion
Ollama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers

Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quantization in fs/ggml/gguf.go and server/quantization.go (WriteTo()), the server reads past the allocated heap buffer. The leaked memory contents may include environment variables, API keys, system prompts, and concurrent users' conversation data, and can be exfiltrated by uploading the resulting model artifact through the /api/push endpoint to an attacker-controlled registry. The /api/create and /api/push endpoints have no authentication in the upstream distribution. Default deployments bind to 127.0.0.1, but the documented OLLAMA_HOST=0.0.0.0 configuration is widely used in practice (large public-internet exposure observed).

Affected products

ollama/ollama
  • <0.17.1

Matching in nixpkgs

pkgs.ollama

Get up and running with large language models locally

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gollama

Go manage your Ollama models

  • nixos-unstable -
    • nixos-unstable-small 2.0.5
  • nixos-26.05 -
    • nixos-26.05-small 2.0.4

pkgs.ollama-cpu

Get up and running with large language models locally

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-cuda

Get up and running with large language models locally, using CUDA for NVIDIA GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-rocm

Get up and running with large language models locally, using ROCm for AMD GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-vulkan

Get up and running with large language models locally, using Vulkan for generic GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pkgsRocm.ollama

Get up and running with large language models locally, using ROCm for AMD GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nextjs-ollama-llm-ui

Simple chat web interface for Ollama LLMs

  • nixos-unstable -
    • nixos-unstable-small 1.2.0
  • nixos-26.05 -
    • nixos-26.05-small 1.2.0

pkgs.gnomeExtensions.ollama-usage-rings

Shows your Ollama Cloud session and weekly usage as colored ring indicators in the GNOME top bar, with pace/burn-down details. Requires your own ollama.com session cookie (entered in the extension settings).

  • nixos-unstable -
    • nixos-unstable-small 3

Package maintainers

Untriaged
Permalink CVE-2026-5530
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Not Defined (X)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Ollama Model Pull API download.go server-side request forgery

A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Ollama
  • ==18.1
  • ==18.0

Matching in nixpkgs

pkgs.ollama

Get up and running with large language models locally

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gollama

Go manage your Ollama models

  • nixos-unstable -
    • nixos-unstable-small 2.0.5
  • nixos-26.05 -
    • nixos-26.05-small 2.0.4

pkgs.ollama-cpu

Get up and running with large language models locally

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-cuda

Get up and running with large language models locally, using CUDA for NVIDIA GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-rocm

Get up and running with large language models locally, using ROCm for AMD GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-vulkan

Get up and running with large language models locally, using Vulkan for generic GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pkgsRocm.ollama

Get up and running with large language models locally, using ROCm for AMD GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nextjs-ollama-llm-ui

Simple chat web interface for Ollama LLMs

  • nixos-unstable -
    • nixos-unstable-small 1.2.0
  • nixos-26.05 -
    • nixos-26.05-small 1.2.0

pkgs.gnomeExtensions.ollama-usage-rings

Shows your Ollama Cloud session and weekly usage as colored ring indicators in the GNOME top bar, with pace/burn-down details. Requires your own ollama.com session cookie (entered in the extension settings).

  • nixos-unstable -
    • nixos-unstable-small 3

Package maintainers