{"id":"CVE-2026-85180","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-85180","summary":"Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control…","details":"Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifest, and cause the server to issue GET requests to internal hosts including cloud metadata endpoints.","published":"2026-09-03T15:17:39.250","modified":"2026-09-03T15:17:39.250","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ollama/ollama"},{"type":"WEB","url":"https://github.com/ollama/ollama/blob/v0.33.2/x/transfer/download.go"},{"type":"WEB","url":"https://github.com/ollama/ollama/issues/17041"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/ollama-0.30.0-through-0.33.2-ssrf-via-cross-host-tensor-blob-redirect"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T15:17:39.250"}}