CVE-2026-85180: Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to r
Summary
Ollama (an AI model management tool) doesn't properly check where it's being redirected to when downloading tensor-layer models (the numerical data that makes AI models work). This allows attackers to trick Ollama into downloading files from malicious servers or even requesting sensitive information from internal cloud systems that should be private.
Vulnerability Details
7.5(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
network
low
none
none
September 3, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85180
First tracked: September 3, 2026 at 02:09 PM
Classified by LLM (prompt v3) · confidence: 92%