Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifest, and cause the server to issue GET requests to internal hosts including cloud metadata endpoints. | |
| Title | Ollama 0.30.0 through 0.33.2 SSRF via Cross-Host Tensor Blob Redirect | |
| First Time appeared |
Ollama
Ollama ollama |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ollama
Ollama ollama |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-03T14:41:50.099Z
Reserved: 2026-09-03T11:08:17.526Z
Link: CVE-2026-85180
Updated: 2026-09-03T14:41:34.012Z
Status : Received
Published: 2026-09-03T15:17:39.250
Modified: 2026-09-03T15:17:39.250
Link: CVE-2026-85180
No data.
OpenCVE Enrichment
Updated: 2026-09-03T16:45:05Z
-
CWE-918
Server-Side Request Forgery (SSRF)