Vulnerabilities
Vulnerable Software
Ollama:  >> Ollama  >> 0.6.7  Security Vulnerabilities
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.
CVSS Score
9.8
EPSS Score
0.002
Published
2025-12-18
Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint.
CVSS Score
6.9
EPSS Score
0.0
Published
2025-07-22


Contact Us

Shodan ® - All rights reserved