Ollama

cat ollama.log

Arbitrary File Read in Ollama via Tensor Digest Path Traversal

CVE-2026-7020

Arbitrary file read in Ollama via tensor digest path traversal. A malicious OCI registry can trick Ollama into exfiltrating any file on the host — including SSH private keys — in three unauthenticated API calls....

April 25, 2026 · 6 min · David Rochester

From SSRF to Data Exfiltration in Ollama

CVE-2026-5530

SSRF in Ollama’s OCI registry redirect handling. A malicious registry can redirect blob downloads to internal endpoints, bypass hash verification, and exfiltrate full responses via the push API....

April 9, 2026 · 7 min · David Rochester