logo

Ollama Server Exposure Reveals Major AI Security Gaps

ID: 8e27810c-28a5-5f24-909e-a96c46d657f8

STIX ID: report--8e27810c-28a5-5f24-909e-a96c46d657f8

Feed Name: Malware Patrol Blog

Threat Score
75/100

Date Published: 2025-06-20

Date Updated: 2026-06-15

Author: Malware Patrol

...
...

Malware Patrol’s scan found over 14,000 publicly accessible Ollama servers, with a large share running outdated versions susceptible to multiple CVEs (DNS rebinding enabling unauthenticated API access and exfiltration, ZipSlip RCE, path traversal, resource exhaustion, and malformed model upload issues). The exposure enables model theft/poisoning and large-scale abuse of inference compute; recommendations include updating to the latest Ollama release, enforcing authentication/firewalls, and monitoring usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.