Ollama Server Exposure Reveals Major AI Security Gaps
ID: 8e27810c-28a5-5f24-909e-a96c46d657f8
STIX ID: report--8e27810c-28a5-5f24-909e-a96c46d657f8
Feed Name: Malware Patrol Blog
Malware Patrol’s scan found over 14,000 publicly accessible Ollama servers, with a large share running outdated versions susceptible to multiple CVEs (DNS rebinding enabling unauthenticated API access and exfiltration, ZipSlip RCE, path traversal, resource exhaustion, and malformed model upload issues). The exposure enables model theft/poisoning and large-scale abuse of inference compute; recommendations include updating to the latest Ollama release, enforcing authentication/firewalls, and monitoring usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
