CVE-2024-28224Disclosure(ollama / ollama)

LOWCVSS 6.6 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch ollama ollama systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ollama

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ollama

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-25: 1Exploit Tool / Code · 2026-08-25: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-25: 108-25
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Cytex@cytexsmb
    Disclosure

    A single webpage visit can permanently poison your local AI model. Oasis Security has disclosed CVE-2026-65105 in NVIDIA's NemoClaw, allowing an attacker-controlled webpage to take unauthenticated control of a local Ollama instance and plant persistent hidden instructions inside the model. The attack uses DNS rebinding to reach Ollama's unauthenticated API on port 11434. NemoClaw binds Ollama to 0.0.0.0 on Windows. This makes the API reachable from the browser and bypasses the Host header validation that Ollama introduced to prevent exactly this attack (CVE-2024-28224). Once the API is reachable, a modified Go template writes attacker-controlled text to every system message at inference time. The poisoning persists across conversations and is invisible to API consumers. NVIDIA fixed the issue on macOS and Linux in v0.0.35. The Windows and WSL path remains unfixed. The local AI infrastructure is becoming an attack surface accessible through the browser. Sandboxing protects the endpoint, but compromising the agent gives the attacker access to its tools. Organizations deploying local AI models need to consider whether their inference endpoints are exposed and whether browser-to-localhost attack paths are being monitored. If you are running local AI models, how are you validating that your inference endpoints are not accessible through the browser via DNS rebinding?

    Post summary

    The advisory details a DNS rebinding vulnerability in NVIDIA’s NemoClaw that allows unauthenticated poisoning of local Ollama models and notes a recent fix for macOS/Linux, but does not claim active exploitation or provide a PoC.

    15063246
    848 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appollamaollama---

Explore more