CVE-2026-5530Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-05: 4Technical Details · 2026-04-05: 304-05
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5530 A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manip… https://www.cve.org/CVERecord?id=CVE-2026-5530

    Post summary

    The post reports a newly discovered flaw in Ollama’s Model Pull API, highlighting the impacted file path but providing no exploit details, patches, or confirmation of active exploitation.

    00010705
    56.8K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5530 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5530 #CVE-2026-5530 #CVE #Medium #CyberSecurity #InfoSec https://t.co/Ai9eAPZKEo

    Post summary

    A new CVE (CVE-2026-5530) is announced with a medium severity (6.3) but no further technical specifics, patches, or exploitation details are provided.

    0000034
    121 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5530 A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manip… https://www.cve.org/CVERecord?id=CVE-2026-5530 ----- Traducción: CVE-2026-5530 Se … http://infoflow.cloud`

    Post summary

    CVE-2026-5530 is a flaw reported in Ollama up to version 18.1 that affects the Model Pull API; the post provides minimal technical details but does not mention a PoC, exploit, active use, or a fix.

    0000039
    63 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5530 - Ollama Model Pull API download.go server-side request forgery Intel Report: https://ift.tt/nowhfVk

    Post summary

    An alert announces CVE‑2026‑5530, describing SSRF in Ollama’s Model Pull API (download.go) and links to an intel report, but no PoC, exploit code, or patch information is provided.

    0000047
    281 followersView on X

Explore more