Description
A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Timeline
| 2026-04-04: | Advisory disclosed |
| 2026-04-04: | VulDB entry created |
| 2026-04-04: | VulDB entry last update |
Credits
davidrochester (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/355283 (VDB-355283 | Ollama Model Pull API download.go server-side request forgery)
vuldb.com/vuln/355283/cti (VDB-355283 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/782107 (Submit #782107 | Ollama 18.1 and previous Server-Side Request Forgery)
