BREAKING: CVE-2026-85180 lets Ollama model pulls reach internal hosts
This story is from 2026-09-03. It is preserved in the archive; the latest stories are on the live feed.
Originally published at HOL Ollama can be made to call an internal host while pulling a tensor model. A registry controlled by an attacker can return a tensor-layer manifest whose blob request redirects to a private address, including a cloud metadata endpoint. The pull API does not require the vic…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-03 14:42 · DEV Community — AI
BREAKING: CVE-2026-85180 lets Ollama model pulls reach internal hosts