Ollama patches a run of critical flaws, including a Windows update bug enabling silent code execution
Security researchers at CERT Polska and Cyera, along with several vulnerability trackers, have catalogued a series of flaws in Ollama, the open-source platform for running language models locally. Cyera's Bleeding Llama research (CVE-2026-7482, CVSS 9.1) described an unauthenticated memory leak that could expose prompts, system prompts and environment variables, and said up to 300,000 servers may be exposed. CERT Polska said an unauthenticated path traversal in the /api/pull endpoint (CVE-2026-103663) could lead to root code execution on restart, fixed in version 0.35.0.
Bottom line — Cyera counts roughly 300,000 exposed Ollama servers, and the software ships with no authentication on its API by default.
Go deeper 6
-
CERT Polska says CVE-2026-42248 and CVE-2026-42249, affecting Ollama for Windows, chain together so an attacker can deliver a payload that runs automatically through the silent update mechanism; it tested versions 0.12.10 to 0.17.5.
-
The Ollama maintainers did not respond to the Windows update reports, according to CERT Polska, which says they did not provide details of the vulnerabilities or the vulnerable version range.
-
Cyera says the leak is reachable through three API calls and that the documented OLLAMA_HOST=0.0.0.0 setting is widely used, which exposes the server to the public internet.
-
An anonymous GitHub security audit by Leo Sexton (Obisidan) reports 27 findings and says Ollama ships with no authentication, rate limiting or SSRF protection on any endpoint; the author says the security team did not respond within nine days before publication.
-
AI Threat Alert counts 36 known Ollama vulnerabilities, six rated critical, and reports an 18% patch rate and an average of 26 days to patch, according to its own tracking.
-
CVE-2025-63389, a critical authentication bypass affecting Ollama up to and including v0.12.3, is listed by OpenCVE and AI Threat Alert as exposing model management endpoints to unauthenticated users.