Ollama DNS rebinding vulnerability
High severity
GitHub Reviewed
Published
Apr 8, 2024
to the GitHub Advisory Database
•
Updated Mar 27, 2025
Description
Published by the National Vulnerability Database
Apr 8, 2024
Published to the GitHub Advisory Database
Apr 8, 2024
Reviewed
Apr 8, 2024
Last updated
Mar 27, 2025
Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).
References