Database/AI/ML frameworks & serving
Ollama (GGUF parser): Malformed 4-byte GGUF file crashes the server (two HTTP requests)
CVSS 8.2CVE-2024-39720AI/ML frameworks & servingcurated
Impact
Malformed 4-byte GGUF file crashes the server (two HTTP requests)
Who can reach it
Unauthenticated network upload of a crafted GGUF
What to do
Upgrade past 0.1.46; part of Oligo's six-issue Ollama disclosure
References
Related entries
- vLLM: out-of-vocabulary stop_token_ids kill EngineCore and take the model server down until restartCVE-2026-100652 · vLLM (Rust HTTP/gRPC frontend, stop_token_ids validation)High
- GitLab AI Gateway: crafted model metadata redirects model requests and discloses Vertex or Bedrock credentialsCVE-2026-19889 · GitLab AI Gateway (Duo Agent Platform model metadata handling)High
- Docker Model Runner (vllm-metal backend): `trust_remote_code=True` set unconditionally, no sandboxCVE-2026-5817 · Docker Model Runner (vllm-metal backend)High
- GitLab AI Gateway: crafted inline flow config overrides the HTTP Host header and leaks Vertex credentialsCVE-2026-75871 · GitLab AI Gateway (Duo Agent Platform inline flow configuration)High
- Gradio: Command injectionCVE-2023-6572 · GradioHigh
- LangChain: Directory traversal via the template path parameterCVE-2024-28088 · LangChainHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.