Server-Side Request Forgery Vulnerability in Ollama by Ollama
CVE-2026-85180
8.7HIGH
What is CVE-2026-85180?
Ollama is susceptible to a Server-Side Request Forgery attack due to inadequate validation of redirect destinations when pulling tensor-layer models. This vulnerability allows unauthenticated attackers to manipulate the server's behavior, potentially redirecting blob downloads to arbitrary hosts. Attackers can exploit a compromised registry to distribute malicious tensor-layer manifests, prompting the server to issue GET requests to sensitive internal endpoints, including cloud metadata services. This oversight poses significant risks to data integrity and confidentiality within affected environments.
Affected Version(s)
ollama 0.30.0 <= 0.33.2
