← Vulnerability feed

Vulnerability record · CVE-2024-37032 · published 31 May 2024

CVE-2024-37032: Ollama digest validation path traversal enables remote code execution

Ollama · Ollama

Ollama before 0.1.34 fails to validate the format of the model digest (expected sha256 with 64 hex digits) when resolving the model path, so malformed digests such as fewer or more than 64 hex digits, or an initial ../ substring, are mishandled. This path traversal flaw is remotely reachable and has a public exploit write-up, making it a serious risk for exposed Ollama instances.

8.8 CVSS 3.1 High EPSS 90% · top 0.2% CWE-22 · Path traversal
8.8CVSS 3.1 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.8 with network reachability, low privileges, and a public exploit write-up, though not yet in KEV.

What it is

Ollama before 0.1.34 fails to validate the format of the model digest (expected sha256 with 64 hex digits) when resolving the model path, so malformed digests such as fewer or more than 64 hex digits, or an initial ../ substring, are mishandled. This path traversal flaw is remotely reachable and has a public exploit write-up, making it a serious risk for exposed Ollama instances.

Impact

An attacker can traverse outside the intended model directory and write or read files, which the public exploit chain escalates to remote code execution on the host. This gives full compromise of the Ollama service and potentially the underlying system.

Attack surface

Reached over the network via the Ollama API (CVSS AV:N) with low privileges required (PR:L) and no user interaction (UI:N). Any client able to call the model path handling endpoint can supply a crafted digest.

Exploitation

Not listed in CISA KEV, but EPSS is 0.89633 (99.78th percentile) and a third-party advisory tagged Exploit describes an RCE chain, indicating public exploitation detail exists.

What to do

  • Upgrade Ollama to 0.1.34 or later, which adds digest format validation.
  • Do not expose the Ollama API to untrusted networks; bind to localhost or restrict access with firewall rules and authentication.
  • Run Ollama with least privilege and in a container or sandbox to limit file write and RCE impact.
  • Monitor for and reject model pull requests containing digests that are not exactly 64 hex characters or that include path traversal sequences.

Detection

  • Inspect Ollama API request logs for digest parameters that are not 64 hex characters or that contain ../ sequences.
  • Alert on unexpected file creation or modification in model storage directories outside normal model files.
  • Monitor for child processes spawned by the Ollama service, which may indicate post-exploitation RCE.
  • Track outbound connections from the Ollama host to unknown destinations following suspicious model operations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-37032 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-63389Ollama missing authentication for critical function vulnerabilityA critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exp…EPSS 0.71%8.8CVE-2026-7482Ollama out-of-bounds read vulnerabilityOllama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied…EPSS 0.71%8.7CVE-2025-15514Ollama vulnerabilityOllama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functiona…EPSS 0.78%8.2CVE-2024-39720Ollama out-of-bounds read vulnerabilityAn issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starti…EPSS 2.5%7.7CVE-2026-42249Ollama path traversal vulnerabilityOllama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP respon…EPSS 0.52%7.7CVE-2026-42248Ollama download of code without integrity check vulnerabilityOllama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows impl…EPSS 0.33%7.5CVE-2026-15685Ollama vulnerabilityOllama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial…EPSS 0.72%7.5CVE-2026-5757Ollama out-of-bounds read vulnerabilityUnauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the serve…EPSS 0.74%

Source: NIST National Vulnerability Database (record CVE-2024-37032), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.